Home Support

AVG Support Community

Share tips and solutions on AVG Products

Have a question?

Community topics

AVG Gurus

These community experts are here to help

  • (AB) Alan Binch
  • (BA) Borislav Angelov
  • (VB) Vladimir Bartl
  • (SK) Subhadeep Kanungo
  • (MS) Miloslav Serba
Ioannis MakripouliasIoannis Makripoulias 

VBS:Malware-gen

Hello,

I'm using the AVG free version for my computer and since this morning I m getting a threat blocked alert from AVG saying about a VBS:Malware-gen detection in Google Chrome (C:\Program Files (x86)\Google\Chrome\Application\chrome.exe).

After a full scan the antivirus detected a large number of files that are infected. In a quick search in Google it seems that Avast users has the same problem (https://forum.avast.com/index.php?topic=197572.0) saying this is a false positive.

Is this really a false positive? Is there anyone else with the same problem?

Thank you

 
KarthikeyanKarthikeyan (Foundever) 
Hello Ioannis,
We are sorry for the inconvenience caused. To assist you better, could you please send us the screenshot(http://avgclick.me/getscreenshot) of the AVG threat message you receive? So, that we can check the same and assist you further.
Thank you
Ioannis MakripouliasIoannis Makripoulias
Yes I can and I will when I manage to find time for it, though, the message I was getting is exact the same as John J's message that has a screenshot attached (or the message described by Chris C) and also the same as many many more users I found in many forums so I really don't see any point in this.

Additionally the problem is now well known and other companies have already post an announcement or an apology for this because it was a false positive (for example Avast: see comments in https://blog.avast.com/behavior-shield-our-newest-behavioral-analysis-technology or https://forum.avast.com/index.php?topic=197572.0). I don't know why are you still asking for something that you must know already. As I can see, the problem was in the definition 170221-1 that is the same definition Avast and I think Norton free version uses (!! - I realised this today) and has been already solved with definition 170222-0 that became available at 10:00 AM approximately.

The problem is that after this false positive and also a totally lack of any official answer from you I did a full scan and AVG deleted or quarantined a large number of files so I must go for a system restore.

I am a friend of AVG for too many time and I understand I'm using the free version but after the second false alarm in 2 months causing me a full system restore, unfortunatelly, I think I'm gooing to look for an alternative.

If you really care even a little about your customers, an official announcement would be the least you can do right now for people like Chris C or John J that still think they got a malware infection.

Thank you for your time

 
Eric MEric M
I am also having this issue and would love any updates.

Had AVG Free 2016 which seemed to be acting up (scheduled scans weren't running as I would expect). So uninstalled 2016 (with the remove utility) and installed 2017. First scan shows 433 VBS:Malware-gen results.
KarthikeyanKarthikeyan (Foundever) 
Hello Joannis and Eric,
Thank you for the information, this seems to be a false detection. We suggest you to update AVG and check if that fix the issue.
Thank you
Peter SmithPeter Smith
Are these hits still considered false positives?  I recieved two hits in seperate "wuapp.exe" files so I'm hesitant to scrub them until I can confirm they are truly infected.  The pathways to the infected files for the "Win32"Malware - gen" virus are the following:

C:\Windows\SysWOW64\wuapp.exe

C:\Windows\winsxs\wow64_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.6.7601.23806_none_8269c95a6c049af7\wuapp.exe

 
Abirami ShanmugamAbirami Shanmugam (Avast)
Peter,
Please be informed that 'wuapp.exe' is a shortcut for Windows update. Hence it is a false positive. You can report false positive from AVG at https://www.avg.com/submit-sample .
Thank you.
Ask a question
Struggling with non-AVG technology? We can fix that, too!