Author Topic: Corrupted 'Delete' button?! VBS:Malware-gen on a Mac?!  (Read 1958 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Corrupted 'Delete' button?! VBS:Malware-gen on a Mac?!
« on: February 23, 2017, 12:24:28 AM »
I am a Macbook Pro user. OS X El Capitan current operating system.
Yesterday afternoon, the Avast Mac Security 2016 notified me that 2 infections were blocked, and my internet program wasn't even open. They immediately went to the chest, as should be the case. However, when I did a system scan, it found some 25 or 50 infected files. After sending those files to the chest, I re-scanned, and it found 80 more infected files. After sending THOSE files to the chest, the numbers finally decreased. I got 31, and then I got 25, then 12... all to the chest.

The next day, I scanned again. This time, it found 51 infected files and 22 unable to scan. I sent them to the chest. Then it blocked four random viruses, all of them were VBS:Malware-gen and all were in my AvidAppManHelper ... whatever that is. I have Avid Media Composer, and it seemed that was what the virus attempted to attack first, because most of the first infected files were in its application files.
After scanning a few more times, it found first 12 infected and 1 unable to scan, then 16 infected and 21 unable to scan.
This came as no surprise to me since I learned that 'worm' viruses will navigate randomly throughout the system, and looking at the locations of the infections, it is quite clear that it is following a random path since every four files are from relatively the same locations.
I decided at this point that I should delete some of the infected files. Practically EVERY '.dmg' file was infected (everything else was .data, .dat, .bf-head, .bf-tail, .index and the like), and since the software for each was already installed, I decided it was okay to remove them.
I hit the 'delete' button, and this message came up: "Restore selected items?" and I am thinking 'no, I said to delete.' So I went ahead and 'restore-deleted' the files. They were not deleted, but rather restored to their original locations. It gets worse.
I started another scan, and it turned up 0 infected files, but 39 files unable to scan. Among them were all the files I attempted to delete.

I have heard that VBS:Malware-gen has been known to tamper with the functions of computer security systems, but from my searches, it has only come up recently that this virus ever appeared on OS X, and most reports come from PC users.
The only websites that addressed this issue all said I needed to install MacBooster. I did so reluctantly, and it allowed me to scan my computer for issues. The system status was 'dangerous' and 'serious' and it offered to fix the problems. I selected 'Fix' and a pop-up arose stating that it fixed nearly 100 of the issues, but if I wanted it to do any more at a time, I would have to pay for such functions, since my current version was 'trial.'
Fortunately, I never put private identity information anywhere, so the virus has nothing to find. Unfortunately, this means I have never made online purchases except with gift cards, so I can't activate the software.
The weirdest thing was that it found all the infected files and stuff in its virus & malware scan, but after I 'restore-deleted' with Avast, it only turned up 1 issue: It wants me to automatically check for updates, including apps, OS X, System Data files, Security Updates...
But I only have it not auto-updating apps and OS X.

P.S.: After all this scanning, I am only able to view 5 2/5 of my virus scan reports... the last one showing just enough that I can hit the button to open the report. Scrolling doesn't even happen, it's like a flat image with functioning buttons. Expanding the window does nothing, either.
« Last Edit: February 23, 2017, 12:34:47 AM by MAC bookworm »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Corrupted 'Delete' button?! VBS:Malware-gen on a Mac?!
« Reply #1 on: February 23, 2017, 12:48:35 AM »
The  VBS:Malware-gen today was a false positive that should be fixed now

Forum is full of posts if you look around


REDACTED

  • Guest
Re: Corrupted 'Delete' button?! VBS:Malware-gen on a Mac?!
« Reply #2 on: February 23, 2017, 01:02:05 AM »
The  VBS:Malware-gen today was a false positive that should be fixed now

Forum is full of posts if you look around

Oh? But the only posts I've seen pertained to PC and Windows.
What about the corrupted 'Delete' button? And the obvious path of corrupted files?
The virus is a worm, and it did travel randomly, infecting some 4 files at a time and then moving on.
I'm pretty sure this is not a false positive.
But it having been rooted at something in my Avid Media Composer software files, I'll grant you permission to doubt it.

P.S.: how do I delete a reply to a post?