Author Topic: Strange Win32:NtfsCorrupt-H [Expl] event  (Read 1480 times)

0 Members and 1 Guest are viewing this topic.

Offline KDibble

  • Sr. Member
  • ****
  • Posts: 229
Strange Win32:NtfsCorrupt-H [Expl] event
« on: January 25, 2021, 05:23:23 PM »
The Avast Web Shield is complaining about something in some messages I'm receiving in a listserv. In one case Avast deleted the entire message body; in another it just "removed" something. The listserv does not permit attachments but it does allow embedded images in email. I'm guessing this was an embedded image. The console reports this as (anonymized):

Incoming email [subject] (C:\:$i30:$bitmap that screws filetable)' From: [somebody], To: [some list]|>PartNo_0#2926903936

The strange thing is that others on the listserv, in replying to the message, don't seem to have seen a problem with it. They are treating it as an ordinary message. Nothing gets quarantined so there's nothing I can upload to VirusTotal. What's going on here?

Thanks.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

Offline KDibble

  • Sr. Member
  • ****
  • Posts: 229
Re: Strange Win32:NtfsCorrupt-H [Expl] event
« Reply #2 on: January 25, 2021, 07:13:58 PM »
Yes, I  did see that thread shortly after starting this one. However, the conclusion in that thread is that Avast should not be blocking a mere image of some text. It should only block things that are actually executable. I had said, above, that I thought what was being removed from these emails by Avast was an embedded image. I have now checked these messages in the webmail for the account, which is not subject to Avast. I can't actually find anything in those messages that looks suspicious.

The subject line in the webmail is: how to counter Block Recent NTFS 0day(C:\:$i30:$bitmap that screws filetable)

That full line is present in both the webmail and my email client. The webmail and my email client access the same email account.

In the case where Avast removed the entire message body in my email client, according to the webmail, all it removed was the following text: "any ideas how to prevent this? are there any patches?" There is no indication in the webmail of any embedded images or attachments. If my webmail provider had silently removed them, then how could they have been downloaded to my email client, where Avast saw them? In the case where Avast claimed to have removed something from the email, I can find nothing in the webmail that is missing in the downloaded copy seen by Avast. It's almost as though Avast simply reacted to the contents of the subject line--but did not remove it--and then, in the one case, removed a completely harmless unrelated line of text, and in the other case, falsely reported removing something else.

Does this make any kind of sense?