cancel
Showing results for 
Search instead for 
Did you mean: 
singh_pranav
Level 7

How to remove HEUR_PDFEXP.E

Hello,

My Windows 8 based system is running McAfee Total Protection. It got infected by Heur_pdfexp.e and McAfee Total protection wasn't able to detect it. It was detected when I seen an email with a pdf attachment to my work email and McAfee Eterprise flagged it.

I ran a full scan and still no results. There are no references to this virus in the community or in the virus definitions.

Does anyone know what to do here?

thanks in advance for help.

0 Kudos
13 Replies
catdaddy
Level 20

Re: How to remove HEUR_PDFEXP.E

You may try running the Latest McAfee Getsusp Tool to see if it detects it as a Suspicious/Unknown File/Program. When doing so please remember to add your Email Address under "Preferences" before scanning. Follow up with Malwarebytes (Free) for a second opinion.

Follow the instructions just before Downloading/Installing to keep it free. These Superb Free Tools and more, can be obtained here:

You can upload the File to www.virustotal.com  and see what other Anti-Virus engines determine as well.

All the very BEST

Catdaddy

McAfee Community Moderator

Consumer Products.

Cliff
McAfee Volunteer
singh_pranav
Level 7

Re: How to remove HEUR_PDFEXP.E

Hi CatDaddy, Thanks for your quick response. I ran the file in VirusTotal and got a 1/56 detection. TrendMicro was able to flag it.

TrendMicro    HEUR_PDFEXP.E    20150216 

This PDF document has an  invalid cross reference table.

This PDF document has 1 page, please note that most malicious PDFs have only one page.

This PDF document has 14 object start declarations and 14 object end declarations.

This PDF document has 3 stream object start declarations and 3 stream object end declarations.

This PDF document has a cross reference table (xref).

This PDF document has a pointer to the cross reference table (startxref).

This PDF document has a trailer dictionary containing entries allowing the cross reference table, and thus the file objects, to be read.

Running other tools like Adware and MalwareBytes didn't detect this file as an issue.

Is the invalid cross reference table causing the malware engines to think that the file has a malware?

Or my only alternative is to buy TrendMicro and clean the file with it.

thanks again.

0 Kudos
exbrit
Level 21

Re: How to remove HEUR_PDFEXP.E

It should have been detected as it's been on McAfee's books for ages now, since 2013 to be exact and listed under a different name:  RDN/Downloader.a!ms!0B8762D1E841 | Virus Profile & Definition | McAfee Inc.- However I suppose a new variant may slip by the filters.   As Catdaddy had suggested, running the GetSusp tool would be the best method so the labs get hold of it.

singh_pranav
Level 7

Re: How to remove HEUR_PDFEXP.E

Thanks Ex_Brit. Running GetSusp opened a whole new can of worms. It is reporting 68 suspicious files and 27 unknown files but the list doesn't have the .pdf file that caused the issue. The zipfile size is exceeding 10Mb so the tool cant send to labs.

I have uploaded the logfiles only through the tool.

0 Kudos
exbrit
Level 21

Re: How to remove HEUR_PDFEXP.E

Whoops, that's too bad.   Best get a 2nd opinion, try AdwCleaner and Malwarebytes Free, both linked in my signature below, last link.

Note the instructions there on how to keep Malwarebytes free of charge.

Maybe that HEUR_PDFEXP.E file is held in Quarantine?   Open SecurityCenter, go to Navigation and scroll down to

Quarantined and Trusted Items and expand those areas.

Toronto ▪ Canada
Volunteer Moderator - Consumer Products
I CAN'T HELP PRIVATELY - PLEASE POST IN THE FORUMS
Use Advanced Search To Find Answers

Consumer Technical Support (alter Country @ top right as needed)

Consumer Customer Service (Accounts, Billing, Registration, etc.)
Anti-Spyware/Malware/Hijacker Tools

singh_pranav
Level 7

Re: How to remove HEUR_PDFEXP.E

Thanks Peter. I ran both Malware byte and AdwCleaner and both didn't report any issue.

The HEUR_PDF.E file is not quarantined. It is still in the same folder as before and hasn't been flagged or quarantined by any of the programs.

0 Kudos
exbrit
Level 21

Re: How to remove HEUR_PDFEXP.E

In that case is it possible to zip that file only and encrypt it/password-protect it using the word infected  ?  Then email file to: virus_research@mcafee.com and make the header of the email start with the word FALSE - for example FALSE (possibly):  file not detected by McAfee


More instructions here:

0 Kudos
exbrit
Level 21

Re: How to remove HEUR_PDFEXP.E

Actually I should have given you the official link first, sorry.

Submit a Virus or Malware Sample | McAfee Labs

0 Kudos
singh_pranav
Level 7

Re: How to remove HEUR_PDFEXP.E

Submitted the infected zip file an got a confirmation. Thanks Peter, Catdaddy for your immediate responses. Will keep you posted as I hear back.

0 Kudos