Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Infection Reported OS X


  • Please log in to reply

#1
WanderZ

WanderZ

    Member

  • Member
  • PipPipPip
  • 130 posts

Hi all,

 

I'm running macOS Sierra v. 10.12.3. I received several popups from Avast reporting 'Infection Blocked' Infection: VBS:Malware-gen URL: https://clients1.goo...t=Google ChromeFile:{gzip}. They were continuous and started after I was on facebook and checked out a new friend request which turned out to be suspicious. I usually, just delete and report the request. So, I ran Avast and it is reporting about 41 infections found all of them say VBS:Malware-gen in the infection details. A couple of the locations are listed below. Should I be concerned that this is targeting Mac or is this a windows issue that Avast is detecting? 

 

Thank you!

John

 

 

 

/Applications/iMovie.app/Contents/Frameworks/Flexo.framework/Versions/A/Frameworks/FaceCoreEmbedded.framework/Versions/A/Resources/fc-sw-4.dat

 

 

/Applications/Xcode.app/Contents/Developer/Platforms/AppleTVSimulator.platform/Developer/SDKs/AppleTVSimulator.sdk/System/Library/PrivateFrameworks/FaceCore.framework/fc-sw-4.dat

 

 

/Applications/Xcode.app/Contents/Developer/Platforms/WatchSimulator.platform/Developer/SDKs/WatchSimulator.sdk/System/Library/PrivateFrameworks/FaceCore.framework/fc-sw-6.dat

 

/System/Library/Assets/com_apple_MobileAsset_DictionaryServices_dictionaryOSX/558f4da14294a6eb6203c03e6bb582f0042eab9e.asset/AssetData/Thai.dictionary/Contents/Resources/EntryID.data

 

 

/System/Library/Security/tokend/uiplugins/CACViewerPlugin.bundle/OBTB.dat

 

These are a sample of the files detected and most are in those directories just different files.

 

Thanks again!


  • 0

Advertisements


#2
greeleyjoe

greeleyjoe

    New Member

  • Member
  • Pip
  • 2 posts

I'm getting exactly the same thing but seems to happen when I login to my Reagan.com email account. Kinda weird, doesn't seem right.


  • 0

#3
WanderZ

WanderZ

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

I'm getting exactly the same thing but seems to happen when I login to my Reagan.com email account. Kinda weird, doesn't seem right.

Ya, from what I found, others have had the same problem with respect to an individual site as well. My issue is not connected with a site when it happens. There were a lot of older threads dealing with the issue but, none that I could find that were not site specific. It's driving me nuts. Should probably just get rid of Avast and not worry about it. That seems to be the common response.


  • 0

#4
greeleyjoe

greeleyjoe

    New Member

  • Member
  • Pip
  • 2 posts

I downloaded the latest antivirus updates a couple of times....and booted my mac a couple of times, ran another scan and nothing! No issues now.  Go figure. Avast must have picked up on the issue and fixed something I'm guessing.


  • 0

#5
WanderZ

WanderZ

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 130 posts

I also updated my virus definitions and rescanned and all is well. I also scanned with malwarebytes for mac and nothing popped up. That was pretty crazy. Thanks!


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP