Autoupdate malware Trojan.Spy.OSX?

macOS specific usage questions
AkiSen
New Cone
New Cone
Posts: 1
Joined: 23 Jul 2017 10:46

Autoupdate malware Trojan.Spy.OSX?

Postby AkiSen » 23 Jul 2017 11:03

I today downloaded a latest version of VLC. I normally double-check this file with checksum and via codesign if it is signed. But today i tried upload it on metadefender and virus total. .dmg file is fine clean but inside is file named Autoupdate. I extract it and upload direct file to virustotal and VT says it is malware. I upload it to Metadefender and Jotti scanner and result is same. Here are result. What it is?

https://www.virustotal.com/en/file/123d ... 5/analysis
https://www.metadefender.com/#!/results ... r/analysis
https://virusscan.jotti.org/en-US/files ... j94f18nckx

Checksum of this file

MD5: 637d80c49c3677645766a29b08877b51
SHA1: 61c984dd5a53310bc4ec4a960e49410cda9dfb3e
SHA256: 123de51952ae2ee69cf94514355f3e04b613dc66b64da628eefc5a371fada0d5

Location:
VLC.app/Contents/Frameworks/Sparkle.framework/Versions/A/Resources/Autoupdate.app/Contents/MacOS/Autoupdate

dfuhrmann
Developer
Developer
Posts: 1183
Joined: 02 Jul 2012 11:09

Re: Autoupdate malware Trojan.Spy.OSX?

Postby dfuhrmann » 05 Aug 2017 08:32

Looks like a false positive, as all other virus scanners show green.

Just make sure to download VLC only from videolan.org, and if you checked that the Codesign signature is from Videolan, then you should be fine. The file in question is the update application used to install updates for VLC.


Return to “VLC media player for macOS Troubleshooting”

Who is online

Users browsing this forum: No registered users and 15 guests