Author Topic: Win32:Evo-gen [Susp] false positive (suspected)  (Read 8035 times)

0 Members and 1 Guest are viewing this topic.

Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Win32:Evo-gen [Susp] false positive (suspected)
« on: December 19, 2013, 02:38:58 AM »
Hi guys,

I have a web pages and there goes download page.
When I try to download file from my webpages avast is reporting Win32:Evo-gen [Susp] virus detection on the file being downloaded (it might be download process also or something).
My first though was that server is infected/hacked (not excluded it is really like that) so took ftp and downloaded files locally to my box (the same ones being reported infected on the very same box also). After ftp download, I ran avast virus check on those files and then files were being reported as clean.
Files being downloaded are .rar and .zip format.

How can I help you to check and sort this out? What might be different with desktop scan and browser plugin scan? How can i change download process not to trigger named virus detection.

Best regards,
K.

P.S. I don't want to scare my customers that they are downloading virus infected files!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #1 on: December 19, 2013, 02:41:00 AM »
Quote
Win32:Evo-gen [Susp]
susp = suspicious  .....so not virus yet




You can upload files and report issues to avast  here : http://www.avast.com/contact-form.php  (select subject according to Your case)

You can use mail
send to virus@avast.com in a password protected zip file
mail subject:  False Positive / undetected sample (select subject according to your case)
zip password:  infected

or you can send files from avast chest
how to use the chest.    http://www.avast.com/faq.php?article=AVKB21






Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #2 on: December 19, 2013, 02:42:03 AM »
Also, can I have the URL and the file in a zipped format via wikisend?

Please PASSWORD PROTECT the file and pm me the password you used. Thanks!
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #3 on: December 19, 2013, 02:42:58 AM »
What exact version of avast are you using?
What vps version?
What os/service pack?
What is the website? (Please make the link not clickable!)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #4 on: December 19, 2013, 02:44:00 AM »
Also, can I have the URL and the file in a zipped format via wikisend?

Please PASSWORD PROTECT the file and pm me the password you used. Thanks!
he cant PM as he only have 1 post 


Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #5 on: December 21, 2013, 03:13:57 PM »
sorry for delay.. i'll try to do all above in a few days from now on..

Cheers,
K.

Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #6 on: December 22, 2013, 01:36:04 AM »
here is the link for download
Code: [Select]
www.cting.hr/eng/download.aspx?cid=8765E9A5-5A0D-457D-A67F-E4EB9265D3C4&v=3.1&t=zip
www.cting.hr/eng/download.aspx?cid=8765E9A5-5A0D-457D-A67F-E4EB9265D3C4&v=3.1&t=rar

you just need to hit download button.

Avast I use is free home edition, the latest version. Application I made is .NET application and the web is asp.net 2.0. Download process is not direct download link, so I suppose this is something that is triggering FireFox Avast plugin detecting above mentioned thing. As for zip/rar file being downloaded I'm 99% sure it's not infected and desktop virus scan is reporting them both clean.

Cheers,
K.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #7 on: December 22, 2013, 02:24:50 AM »
The real problem is that you don't use a dedicated/own server.
You are using a hosting service where they put multiple domains/sites on the sam IP.
http://zulu.zscaler.com/submission/show/e5540bdb273e54b4e0a1ed7d11f3fd61-1387675223

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2294
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #8 on: December 22, 2013, 10:27:31 AM »
here is the link for download
Code: [Select]
www.cting.hr/eng/download.aspx?cid=8765E9A5-5A0D-457D-A67F-E4EB9265D3C4&v=3.1&t=zip
www.cting.hr/eng/download.aspx?cid=8765E9A5-5A0D-457D-A67F-E4EB9265D3C4&v=3.1&t=rar

you just need to hit download button.

Avast I use is free home edition, the latest version. Application I made is .NET application and the web is asp.net 2.0. Download process is not direct download link, so I suppose this is something that is triggering FireFox Avast plugin detecting above mentioned thing. As for zip/rar file being downloaded I'm 99% sure it's not infected and desktop virus scan is reporting them both clean.

Cheers,
K.
Hello,
thanks for the samples, false positive will be fixed in next stream update.

Milos

Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #9 on: December 22, 2013, 11:21:22 PM »
The real problem is that you don't use a dedicated/own server.
You are using a hosting service where they put multiple domains/sites on the same IP.
http://zulu.zscaler.com/submission/show/e5540bdb273e54b4e0a1ed7d11f3fd61-1387675223

but this is the most common case of hosting, and thus shouldn't be triggered as maleware site imo.

K.

Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #10 on: December 22, 2013, 11:22:04 PM »

Hello,
thanks for the samples, false positive will be fixed in next stream update.

Milos

tnx for the update.

K.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #11 on: December 22, 2013, 11:35:12 PM »
It is not that site that is blocked for malware, it is the IP that is because some other site on the same IP is malicious.

Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #12 on: December 25, 2013, 08:20:20 PM »
It is not that site that is blocked for malware, it is the IP that is because some other site on the same IP is malicious.

So in other words if IP is being recorded to be potential malicious source, then host header name can be recorded also, isn't it? Could that be resolution to all the problems filtering out not malicious sites on the IP. Personally I cannot force my ISP to filter out malicious sites (especially if I don't know which of them are the ones causing problems), and on the other hand switching to another ISP could result with  the same problem.

K.

Offline KeiserSoze

  • Newbie
  • *
  • Posts: 14
Re: Win32:Evo-gen [Susp] false positive (suspected)
« Reply #13 on: August 12, 2023, 07:43:46 AM »
For security reasons, can this thread be PURGED or set as PRIVATE?

K.