Why is PUA.OSX malware available in the App Store?!

Thor Anti-Virus is the sketchiest app ever allowed in the App Store? Please let me know how this is possible? I'm about to jump ship..


Thor Anti-Virus is 110% Malware (Pua.osx)- VirusTot… so Why is the *thing* #3 most popular. I fear this is a sign of the times. Also signed by an untrusted root cert click the first + to see it Antivirus scan for b0bfc0e737d88623a27a2fba4ddb3dfa6898a919351a01385ecc1a586d1fb3b9 at2017-06-12 06:33:54 UTC - VirusTot…


Even apple's own favorite dud Malwarebytes flags this thing...



1) There are obvious fake reviews. It has a suspiciously high number of reviews that come from the must gushing loyal fans ever who have nothing to say but short positive statements that emphasize current sales.

2) The developer is sketchy as anything. Their website is ridiculous and has fake pictures of a supposed "Amelia DyBala" which is so obviously not "her" Link to other Websites who are using the same picture-Google Images

3) The App is awful - U.G.L.Y. as anything looks like it was designed in 1992 and ran in 1990. DOesn't do anything except use clamav which is totally free...total rip off for all of the people paying for it and violation probably of the freeware license that clamav has.

4) It installed itself in /libexec on my computer and was impossible to uninstall

5) It wants to open EVERY. SINGLE. TYPE. OF. FILE. ON. YOUR. COMPUTER...EVERY. SINGLE. ONE. YES. ALL. OF THEM. Why? I don't need it to open word documents that have already been scanned once only to annoy me and waste time trying to get every single file to open in the right app.

6) "Her" other app for file viewing does the same thing where it CAN NOT no matter what be uninstalled and thinks it can open every single file type which it just can't. All it does it give a useless checksum which unfortunately no one uses and if you are smart enough to do that you wouldn't true sketchy Amelia to calculate it for you. More importantly it's just adware for the paid version of Thor ($10!) so basically everytime you go to open a file you get a popup from the app saying buy me now!

7) ITS MALWARE - https://malwr.com/analysis/NDE0NTkyNjAyMGQ4NDhkNGFkZTQxMzA4ZGQxMDI3YmI/


Antivirus scan for b0bfc0e737d88623a27a2fba4ddb3dfa6898a919351a01385ecc1a586d1fb3b9 at2017-06-12 06:33:54 UTC - VirusTot…


So why and how is pua.osx being distributed as #3 app in the App Store? Is it over? Should people divest?

MacBook Pro TouchBar and Touch ID, macOS Sierra (10.12.4)

Posted on Jun 11, 2017 11:55 PM

Reply
7 replies

Jun 12, 2017 1:18 AM in response to chase_daniel

That's a great question, but technically PUA isn't malware. I suspect most everybody here will agree that it's at least scamware in that it's mostly interested in getting your money while doing little if anything to benefit the user, but it's not exactly malicious in the strictest sense of the word.


None of that should be taken as endorsement of Apple's policies with regard to the App Store. They have made recent promises to clean things up and we all hope that apps such as this will be part of that. For years Apple has only screened apps to make certain they abide by App Store rules and a few apps that improperly used user information improperly have been booted, but that's been the extent of it up to now.


As you mentioned, another feature that has been badly abused is the Review process. Developers have frequently offered discounts or other benefits to users that give them good reviews. This developer has apparently programmed bots to post thousands of 5 star reviews without being detected. I understand that Apple announced at WWDC steps to prevent apps from constantly pestering users for a review, but I'd also like to see them do more to police the other parts of the review process.


Oh, and ClamAV has a very liberal licensing policy, so at least that part is OK. It's also being freely used by macOS Server, ClamXav, Sierra Cache Cleaner and most recently Drive Genius 5.

Jun 12, 2017 5:50 AM in response to chase_daniel

chase_daniel wrote:


So why and how is pua.osx being distributed as #3 app in the App Store? Is it over? Should people divest?

No one here can answer questions about why Apple does or does not do something. Speculation about their policies is also prohibited by the Terms of Use. Submit your feedback as LucoBrasi suggests.


If you're using "divest" in its common meaning to pull all your investments out of Apple, well, that's entirely your decision. In my opinion, doing that on the basis of one questionable app is just a bit of an overreaction.

Jun 17, 2017 8:03 PM in response to chase_daniel

there are a myriad of fake, rogue and cloned apps in the app store.

no action taken even after I sent an email to support and was informd]ed they would take action.


i will get to the bottom of this, god willing.


examples:

Awesome Notepad by MOKKA MAHESH

https://appsto.re/ca/-pEOab.i


today I found another pearl:

Sketch.Up - Learn Draw.ing,Scribble in Paint Board by MD. ULLAH

https://appsto.re/ca/c8AB3.i

Doodle Art - Draw.ing,Paint.ing,Sketch.ing Studio by MD. ULLAH

https://appsto.re/ca/saBIZ.i

Sketch.Book - Draw, Drawing.Pad & Paint Scribble by Odyssey Apps Ltd.

https://appsto.re/ca/nwMn7.i

Jun 17, 2017 9:33 PM in response to rexioderum

A few weeks back, Apple announced that they would be "cleaning up" the App Store, starting with apps that crash.


I haven't seen a lot of progress there, but at least they appear to be applying additional resources to that area.


A colleague of mine and frequent contributor here, was successful in getting at least one such app removed, only to find it reintroduced with a new name a few weeks later.


Please keep up the fight and perhaps others will join.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Why is PUA.OSX malware available in the App Store?!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.