macOS Sierra - Detected VBS:Malware-gen [Need Help]

I installed Sierra about a month ago. I have done a few Full System Scan a few times, everything was good.

Today, I logged into one of my macOS accounts. Few Avast popups showed up. Avast detected Malware on files such as:

/Users//Library/Containers/com.apple.siri.media-indexer/Data/albumtitlesdataTable.tdb
/Users//Library/Containers/com.apple.siri.media-indexer/Data/composernamesdataTable.tdb
and other *.tdb files

I logged out, logged in to another macOS account. Did a manual scan of the account’s com.apple.siri.media-indexer/Data directory and Avast detected more malware.

All of them are now in the Virus Chest.

Questions:

  1. What is VBS:Malware-gen?
  2. Why were the malware detected just now?
  3. Are these real malware, or just false positives? Is my system at risk?
  4. What should I do next? :frowning:

I am running a full scan again to see if Avast finds anything.

Thank you so much!

Regards,
Martin

I have the same issue today also 2017-02-21. Avast keep on popping up “VBS:Malware-gen” detection.

I used Malwarebytes and detect nothing.

Right now doing a full system scan ant currently at 75% complete and detected 98 infections. Does not seem like there can be that many infection with so many different files.

Looking it up VBS is suppose to be VB scripts (how is Mac going to use VBScript)?

Might be false positive with the latest update.

I’m having this VBS:Malware-gen problem with Sierra as well today.

Hey guys I am having the same problem, my computer was just working fine, I was doing some doing some codes and when i tried to run it the inflection blocked pop up started. I ran the avast and it is giving me VPS malware gen or something for things like spotlight imovies and other applications and files. Do anyone know why is this happening? It’s freaking me out

Having same problem as well. Anyone have any info to share

I am also having the same problem on El Capitan. I did a full scan and it “detected” viruses in everything from .gif files in excel to iphone apps, 423 total. Hoping the next update fixes this.

My web shield is continuously popping up… extremely annoying!!!

INFECTION BLOCKED!

VBS: Malware-gen

URL: https://clients1.google.com/tbproxy/af/query?client=Google%20Chrome

File: {gzip}

I too am seeing numerous VBS:Malware-gen reports on two Macs running Sierra (OS 10.12.3). I aborted the scans and shut down for the night. I am looking forward to a revision/update to Avast in the morning to correct these apparent false positives. . . unless this is “for real” then I will consider other reactions. :-[

https://forum.avast.com/index.php?topic=197572.0

How do I get all these files RESTORED to their original location from the Virus Chest? The scan put tons of files in the Chest after finding the VBS: Malware Gen which is a false postiive Avast glitch!

Please give clear instructions. Thank you so much!

Me too. Sierra 10.12.3. I did several more scans after the first terrifying one that identified about 90 infected files; I haven’t deleted anything, only put them in the chest, but it started out with about 90 and decreased to 9 files each of the last 2 times. A Malwarebytes scan in the middle of all that turned up nothing. I just now got an Avast update, am running another scan, and so far it’s not flagging anything.

But what now? What do I need to do with all the files that got moved into the Virus Chest?

https://forum.avast.com/index.php?topic=197620.msg1371153#msg1371153

To restore the files :

  • Make sure you have the latest VPS update (with the fix)
  • Place the files back from the chest

How do i get the latest VPS? I tried updating virus definitions through avast and it didn’t work?

So just open the chest and restore everything that was put in there today? Doesn’t it automatically delete things it can’t move?

Thanks for the help.

How do i get the latest VPS?
Wait till avast has released the new VPS version then simply update it.
So just open the chest and restore everything that was put in there today?
Only those things that are detected as VBS:Mal-gen need to be restored. If things are deleted because they (for whatever reason) couldn't be placed in the chest, install the application again (or if it has that option, perform a repair of the application)

If data (documents and such) are deleted, either restore them from the chest or retrieve them through recent backup.

When restoring items from chest I received this error.

The file already exists.

Should I overwrite, skip, overwrite all, skip all, cancel?

Like others I’m waiting for instructions on how to restore files in the Virus Chest.

https://www.avast.com/faq.php?article=AVKB21

After you restore items from the virus chest do they continue to show up in there?

I tried to restore all 3k-ish files and used overwrite all, windows 10 asked me if i wanted to let avast makes changes to my system, i said yes.

All files are still showing as being in virus chest.

I deleted about 500 files or so… Like I actually pressed delete, not virus chest. I was just scared about what the hell might have happened, so I wanted it all gone… But it seems like it was 500 perfectly good files now? And maybe crucial files for programs?

Any solution advice to getting these files back?

If everything is working as it should, not action is needed.

If you get something like e.g :

  • file is missing
  • application that is giving a errror

restore the file(s) from the virus chest.

If that is not possible for whatever reason, some options are (not limited to) :

  • install the application again
  • place a backup of the files back
  • run sfc