Author Topic: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]  (Read 6158 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« on: November 23, 2016, 08:09:02 AM »
My mac book locked up, while web surfing,  on a strange screen i have never seen before, and only way out was to restart. I suspected infection at that point.
After restart i scanned with ClamXav and found several instances of what it calls "phishing" and as it was discovering those, my Avast gave me pop ups of  JS: ScriptIP-inf [trj] alarms.
Restarted and ClamXav kept on increasing the number it found of the JS above.
Then used MBAM and found nothing.
Fearing still being infected intalled MacBooster av and it found no infections just some "bad" cookies.
Tried to remove MacBooster and it was not possible
Then on ReScan with MBAM it found some items related to MacBooster and removed them
Was able to remove,  (move to trash), MacBooster, but its installer icon refuses to go to trash.
Then scanned with Avast again and found and isolated MacOS: VSearch-AL [Cryp]
Feels like i am chasing my tail here !
Am i infected ? I am afraid to use anything with password

REDACTED

  • Guest
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #1 on: November 24, 2016, 08:53:19 AM »
No one can give me a clue ?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #2 on: November 24, 2016, 10:41:35 AM »
Have patience.

Not many people here are using a MAC.

Offline TED123

  • Newbie
  • *
  • Posts: 18
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #3 on: November 24, 2016, 06:09:12 PM »
First off, your choice of MacBooster was not good. ANYTHING IObit (developer name) is basically crapware/malware. Never get sucked into "booster" anything. 95% of the time they are fishing with bait.

Here is what I would do.

Go into your Safari preferences.
 
Safari-->Preferences-->Search--> Disable or uncheck "Preload Top Hit in the background" and "Enable Quick Website Search"  then clear all history and cookies. Leave this as your default setting on every Mac you own.





Then  I would download this program and install it. ( safe program and if this helps you out, please donate something to this developer)

https://freemacsoft.net/appcleaner/   


When using it, hit the "list" icon in the upper right corner.

Then reinstall  MacBooster crapware again. Yes that is what I said. Then use AppCleaner to uninstall MacBooster. Hopefully it will find the pathway to that icon that is persisting. No great loss on doing this since you have nothing to lose since you are already infected.

Then I would reboot.


Run a full Avast scan and Malwarebytes scan. Then I would download the free BitDefender on-demand scanner through the Mac App Store. Make sure you update definitions before you do a full scan. This is only an on-demand scanner so it will not interfere with Avast on-access scanner.


I then would download all the programs from Patrick Wardal, A leading Mac OS X/MacOS malware researcher. Here is an "About" him on his site and then go to his free programs and run all of them that logically would pertain them to your problem. In the VirusTotal linking that is used in most off his programs, go through the lists of every file that is sent to VirusTotal and when you see a "?" mark click on it and "force send" it to VirusTotal with the submit button that comes up. Why this doesn't force send everything I just don't get???

Please read the descriptions and processes of each program that he has posted for each program to get a feel what's happening when you use them. This will help you figuring out IF you are infected or not. Great learning info.

https://objective-see.com/about.html

If you want to load any other Mac anti-virus software ONLY use TOP commonly known brand names that are used in the PC world. Do not use "no name's" even if they are in the Mac App Store.  Only trust the the "Big Boy's" in AV, or you have a great chance in get "MacBoosted" by scam-ware like IObit.

.



« Last Edit: November 24, 2016, 06:29:28 PM by TED123 »

REDACTED

  • Guest
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #4 on: November 25, 2016, 07:11:48 AM »
 I Never use Safari, just Chrome and Firefox on the Mac.
I agree with you on "Macbooster" name, I would never go for names like that,
it was in desperation after having used Avast and MBAM that I was looking for another AV to scan with.
    So MacBooster had nothing to do with this incident that made me suspect I might have gotten a bug.
I was on Chrome, web surfing, not paying much attention, and can not even remember the page i was on,
when the Mac opened a page I could not get out from, and no links on that page worked.
Only way out was ReStarting the Mac which it did regularly.
Since this happened on a Mac,  that is commonly known they don't get "bugs", I was very suspicious something might have gotten through !
    I have been a Windows user for years, and this is my first Mac and my only computer at the moment.
Using Windows  with Avast has kept me safe through the years.
   I find it ironic that I am spending all this time figuring out on a Mac, since "they don't get bugs",
IF I am infected or not. Windows was simpler.


Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #5 on: November 26, 2016, 05:00:29 PM »
Hi qpavlos,

Can you post the file locations of what Avast showed was infected? We can give a better detail on how to proceed (this should be int he scan results screen)


Mac
"People who are really serious about software should make their own hardware." - Alan Kay

REDACTED

  • Guest
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #6 on: November 27, 2016, 08:53:10 PM »
SMH, Mac book with Avast will not allow me to copy / paste the locations !
The only thing i can do is submit to virus lab !

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #7 on: November 28, 2016, 04:31:34 PM »
SMH, Mac book with Avast will not allow me to copy / paste the locations !
The only thing i can do is submit to virus lab !
Attach a screenshot ...

REDACTED

  • Guest
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #8 on: November 28, 2016, 07:54:01 PM »
Screenshot of Avast and MBAM findings

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #9 on: November 29, 2016, 10:32:51 PM »
In the first screenshot, Avast is finding files related to the ClamAV engine, or its quarantined files. Its not uncommon for one AV to flag the definition database for example of another. This is a common temp space for applications. The "TV SHOW, DownloadReal Time Wi.dmg" is likely some legitimate detection but the screenshot doesn't show what the detection was.

Second Screenshot is MBAM, it has removed MacBooster, which is a quite popular piece of Adware(?), it offers to speed up your Mac but does very little if anything, so MBAM removed it as a PUP detection. This isn't really malicious, but it should be removed and it looks like it did.
"People who are really serious about software should make their own hardware." - Alan Kay

REDACTED

  • Guest
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #10 on: January 16, 2017, 06:07:08 AM »
I have MacOS.  Got an infected fake email from "AMEX", had an HTM attached.  I deleted it and emptied trash but still, whenever I open Apple Mail, I get this Avast warning.  How to get rid of this script?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #11 on: January 16, 2017, 09:33:50 AM »
Delete the mail from the server, not just you system/email client.

REDACTED

  • Guest
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #12 on: January 16, 2017, 07:20:43 PM »
 Thanks.  I went back to the server to check to see if the trash has been purged. On that account it had not. So I purged the trash and the problem went away   Thanks for your help.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Macbook with JS: ScriptIP-inf [trj] and MacOS: VSearch-AL [Cryp]
« Reply #13 on: January 16, 2017, 07:30:11 PM »
You're welcome.