Very large Trojan Horse

A little puzzled, have had home edition on a laptop for a while without anything showing up, today a scan showed up a couple of problems which obliged with virus vault deposit.

Just relaced AVG with Avast on my desktop and up pops a potential problem:

                     Malware name: Win32:Agent-LE [Trj]
	         Malware type: Trojan Horse 
	         VPS version: 091120-0, 20/11/2009

On repeat scans this object can only be moved, no access to the Virus Vault stating “ there is not enough space on the disc” - this would make the file size about 25 GB, any ideas please.

Try MBAM and SAS

MBAM http://filehippo.com/download_malwarebytes_anti_malware/
update and run quick scan, click on “remove selected” after scan, this will move anything found to qarantine

SAS http://filehippo.com/download_superantispyware/

Thanks Pondus for the suggestion, downloaded and carried out full scan - nil infections!

Question now even more apparent - why should Avast state not enough space for virus vault?

It could be that the file is too large for the virus chest. There is a limit set on it to prevent it from growing massively large.

  • Can you tell us the name and location of the file?

Right click avast icon–>click ‘Avast log viewer’–>click ‘warning’ section–>look at the bottom of the log (or click the date time header to bring the most recent to the top)

Or check the source file using notepad C:\Program Files\Alwil Software\Avast4\DATA\log\Warning.log and copy and paste the entry.

[li]Can you find the file and see how big it is, and then you can increase the size of the virus chest to accomodate:
right click avast! tray icon → program settings → ‘chest’ tab

-Scott-

I’ll never understand why is it so popular to jump to SAS and MBAM so fast around here.

@RejZoR

No anti virus application is 100% effective against the latest prolific malware purveyors.

Its not about abandoning avast! for SAS or MBAM but about Layered Protection that consists of:

An up to date anti virus application like avast!
An up to date anti malware application like MBAM or SAS but these can be used together as long as olnly one resident protection is active to prevent conflict
A Security Monitor like WinPatrol to watch over other system security aspects.

I think RejZoR is implying that it’s an avast! issue, so advice given should deal with that.

spg SCOTT is on the right track asking for the file name. It will probably be a detection within an archive, an installation file or a large system file like pagefile or hyberfil.

But it’s unlikely to be a single Trojan file, so the advice should not be to move it to the chest but to investigate what the detection is triggered by and whether it’s a false-positive or real. Once we know that we can advise on removal or reporting of a FP.

Here is the file:

C:\Program Files\Alwil Software\Avast4\DATA\moved\pagefile.sys.vir" file.

No success in finding it, nothing in moved folder and search for page file.sys.vir, negative, hence have not established the size - with regard to current max size of chest = 256MB but max size of file to be sent only 1024KB, maybe increase and try again?

This is my first experience with any unwanted issues, meanwhile thanks everyone for your interest.

Ok, FwF was right :wink: Pagefile.sys…

Some more info about pagefile…the first one is relevant to the fact that you told avast! to move it.

http://forum.avast.com/index.php?topic=48480
http://forum.avast.com/index.php?topic=39794

-Scott-

Many thanks Scott, now I know OP’s have been here, should have done more searching before posting but at least it has established this forum as helpful and definitely friendly - will take setting, exclusions route and cross fingers.