Author Topic: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive  (Read 11237 times)

0 Members and 1 Guest are viewing this topic.

beedub

  • Guest
Help! Avast!, which i think is great, keeps removing Winword.exe as a Win32:Evo-gen [susp] but if i restore it and scan it, it is clean. It is the 1999 version. right from the disc - it's clean also. how can i restore it? never had this problem before, have submitted it etc. Need my Word program!

GeoffL

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #1 on: March 17, 2013, 01:05:33 PM »
For info, I have the same problem with my wife's netbook (Asus Eee PC running Win XP Home). We have Word 2000 and have used this for years without issue until the latest Avast definition update.

I can't find a way of excluding Word from on-demand checking (and not sure I'd want to anyway, since Word macros are a major malware vector). So, for the time being, I've switched my wife to Open Office as that can do just about everything she needs Word for anyway. I've reported the false positive, so hopefully Avast will resolve the issue. In the meantime, we'll just have to continue using Open Office or switch to another AV solution.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #2 on: March 17, 2013, 01:05:43 PM »
when you have the file in chest....right click and upload to avast lab as false positive
you may add a link to this topic in case they reply

GeoffL

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #3 on: March 17, 2013, 01:14:36 PM »
I hope what I infer from your post is incorrect as that would imply a major UI failure for Avast. As I understand it, I've already reported the false positive. Here's what I did:
  • Following the first warning, I uninstalled Office 2000 from my wife's machine, removed the associated registry hives, and deleted the Microsoft Office folder in Program Files.
  • Rebooted the computer then carried out a fresh install from the original CD.
  • Tried to launch Word, only to get the same Avast warning.
  • Clicked the link in the warning to report the false positive, and followed on-screen prompts to submit.
Do I also need to right-click and upload the file to the Avast lab? Or is what I've done sufficient?

TIA,

Geoff

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #4 on: March 17, 2013, 01:18:02 PM »
Quote
Do I also need to right-click and upload the file to the Avast lab? Or is what I've done sufficient?
should be ok..... but if file is already in chest, you have the option to do it from there


avast! 7.x: Using the Virus Chest
https://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=1406


beedub

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #5 on: March 17, 2013, 01:22:12 PM »
i removed various recent trial programs that were not needed and restored to 1 week ago- it seems ok now.

GeoffL

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #6 on: March 17, 2013, 01:54:43 PM »
I'd be interested to know whether it stays that way as I suspect that by restoring to a week ago you might have removed the Avast change that started off the whole issue. If so, that issue is likely to return when Avast auto-updates itself (and hence reinstates what caused the FP in the first place).

ChrisB

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #7 on: March 17, 2013, 03:03:00 PM »
Sorry, didn't spot this (searched for Word not winword) and started another thread for the same problem. An upgrade from avast 7.0.1466 to avast 8.0.1483 & reboot had no effect, but I then installed the latest Windows Updates, rebooted again and the problem has gone; Word runs normally.

Not sure what the important change was, it could be that the virus definitions updated at reboot included a fix following your report.

Chris

GeoffL

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #8 on: March 17, 2013, 08:09:00 PM »
We went out for a few hours and, when we came back, my wife opened Word. No Avast warning appeared, so I assume that the FP reports have been acted upon and the fix rolled out. That's what I call speedy service!

minimalist

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #9 on: March 17, 2013, 08:34:01 PM »
Following the advice on this thread, I updated from avast 7.0.1466 to avast 8.0.1483 and I have installed the latest Windows updates.

However, it appears as though my previous version of avast (avast 7.0.1466) deleted Microsoft Word 2000 from my computer when it tried to, I suppose, deal with the false positive. I no longer have the disk for it. Is it possible to actually retrieve an older copy of my Microsoft Word 2000 or am I "screwed" for a lack of a better word.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #10 on: March 17, 2013, 08:37:08 PM »
Quote
Is it possible to actually retrieve an older copy of my Microsoft Word 2000 or am I "screwed" for a lack of a better word.
is there any file in avast chest?

minimalist

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #11 on: March 17, 2013, 08:43:37 PM »
Yes, there are multiple versions of winword.exe in there. One version is last changed from 2002 while the others were last changed from 2013.

minimalist

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #12 on: March 17, 2013, 08:45:13 PM »
Would it just be a matter of right-clicking the oldest file and selecting "Add" or something?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #13 on: March 17, 2013, 08:46:12 PM »
no...restore  file

but you may right click and scan it first to see if still detected

a copy will remaine in chest after restore, just in case. this you may delete when all is OK...no rush to delete anything from chest

avast! 7.x: Using the Virus Chest
https://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=1406

« Last Edit: March 17, 2013, 08:48:27 PM by Pondus »

juliegnh

  • Guest
Re: Avast! is removing winword.exe Win32:Evo-gen [susp], false positive
« Reply #14 on: March 17, 2013, 09:25:18 PM »
Same thing happened to me today on a laptop with Office 2000 on it.  I restored the winword.exe from the chest but had to also exclude it from being scanned until this is fixed.  I did this under Settings, Global Exclusions.  Avast! 8.0.1483.  Is it now fixed?