Avast WEBforum

Other => Viruses and worms => Topic started by: mrapi on December 19, 2013, 07:25:07 AM

Title: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 19, 2013, 07:25:07 AM
On scan: NO THREAT FOUND
On acces: Detected

https://www.virustotal.com/en/file/f145782fe72836ec5cda663c2e904e4aa774e04685f373b85b46b11d9cc1218b/analysis/1387434060/ (https://www.virustotal.com/en/file/f145782fe72836ec5cda663c2e904e4aa774e04685f373b85b46b11d9cc1218b/analysis/1387434060/)

Link to suspect file :   http://www.mediafire.com/download/hfq96m9u38525md/srvliste.zip

Also file sent to support this morning

Thanks
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on December 19, 2013, 07:59:52 AM
report it here.    http://www.avast.com/contact-form.php
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 19, 2013, 08:21:21 AM
Done
thanks!
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Milos on December 19, 2013, 08:49:43 AM
Hello,
it will be fixed in next stream update.

Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 19, 2013, 10:44:13 AM
thanks!
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: lilliana on February 22, 2014, 07:29:59 PM
This virus was flagged numerous times today on my computer.
What to do about it?
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on February 22, 2014, 07:35:13 PM
This virus was flagged numerous times today on my computer.
What to do about it?
For help, follow this guide and start your own topic  http://forum.avast.com/index.php?topic=53253.0

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 14, 2014, 09:29:26 AM
I have a new problem with  Win32:Evo-gen [Susp] - false positive on 2 files :
On scan: NO THREAT FOUND
On acces: Detected

https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)
https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/ (https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/)
Also sent with http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Thanks!
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: REDACTED on June 14, 2014, 12:22:44 PM
I have a new problem with  Win32:Evo-gen [Susp] - false positive on 2 files :
On scan: NO THREAT FOUND
On acces: Detected

https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)
https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/ (https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/)
Also sent with http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Thanks!
Should be fixed soon.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on June 14, 2014, 01:06:34 PM
I have a new problem with  Win32:Evo-gen [Susp] - false positive on 2 files :
On scan: NO THREAT FOUND
On acces: Detected
because Win32:Evo-gen [Susp]  (suspicious) is an on access only detection

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 14, 2014, 03:19:18 PM
Today another one :   https://www.virustotal.com/en/file/24be70a2df94971c05d545935ac5d30188122d4e0af4abcf5432b950e0a6ad61/analysis/1402751849/ (https://www.virustotal.com/en/file/24be70a2df94971c05d545935ac5d30188122d4e0af4abcf5432b950e0a6ad61/analysis/1402751849/)

sent also by  http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 14, 2014, 09:23:47 PM
thanks,one is fixed,this one not: https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/]https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/]https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)

I have a new problem with  Win32:Evo-gen [Susp] - false positive on 2 files :
On scan: NO THREAT FOUND
On acces: Detected

https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)
https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/ (https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/)
Also sent with http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Thanks!
Should be fixed soon.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: REDACTED on June 15, 2014, 02:36:25 PM
thanks,one is fixed,this one not: https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/]https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/]https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)

I have a new problem with  Win32:Evo-gen [Susp] - false positive on 2 files :
On scan: NO THREAT FOUND
On acces: Detected

https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)
https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/ (https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/)
Also sent with http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Thanks!
Should be fixed soon.
Have you sent this one too ?
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Frank2 on June 15, 2014, 06:22:02 PM
Avast reported Win32:Evo-gen [susp] and blocked download/execution of the Western Digital MyCloud installer, downloaded from WD:
 http://support.wd.com/product/download.asp?groupid=904&sid=207&lang=en

 I am unable to use my device.

I have also submitted Ticket Ref # : [[061514-8589471]] to Western Digital.

Is this a false positive, or an actual infection?

I have also attempted to submit a ticket with the file attached, but after unsuccessful several tries I gave up.

Thanks,
Frank
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 15, 2014, 07:15:01 PM
yes,sent,now seems fixed,thanks!

thanks,one is fixed,this one not: https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/]https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/]https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)

I have a new problem with  Win32:Evo-gen [Susp] - false positive on 2 files :
On scan: NO THREAT FOUND
On acces: Detected

https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/ (https://www.virustotal.com/en/file/e612eb3e7b79ca96634004975086c2b4f0cac7a9e88199c16bad807c0ffa6159/analysis/1402730655/)
https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/ (https://www.virustotal.com/en/file/3e650cb2afb93ec5ce5c775d63f8ccc0560d823fa3b82650fca1f826d22722a3/analysis/1402730678/)
Also sent with http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Thanks!
Should be fixed soon.
Have you sent this one too ?
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 20, 2014, 04:17:45 PM
new files:
https://www.virustotal.com/en/file/3c395f8d6cb96438b449dfa956357d50d2076c77ddd2fd934b0a7291472e4d75/analysis/1403273673/ (https://www.virustotal.com/en/file/3c395f8d6cb96438b449dfa956357d50d2076c77ddd2fd934b0a7291472e4d75/analysis/1403273673/)
https://www.virustotal.com/en/file/ac3a3175de710dddfed5afec2bf9de2c89197efbd8bd7772da0e4007c2f9efc6/analysis/1403273691/ (https://www.virustotal.com/en/file/ac3a3175de710dddfed5afec2bf9de2c89197efbd8bd7772da0e4007c2f9efc6/analysis/1403273691/)
 also both sent by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on June 20, 2014, 09:34:11 PM
new files:
https://www.virustotal.com/en/file/3c395f8d6cb96438b449dfa956357d50d2076c77ddd2fd934b0a7291472e4d75/analysis/1403273673/ (https://www.virustotal.com/en/file/3c395f8d6cb96438b449dfa956357d50d2076c77ddd2fd934b0a7291472e4d75/analysis/1403273673/)
https://www.virustotal.com/en/file/ac3a3175de710dddfed5afec2bf9de2c89197efbd8bd7772da0e4007c2f9efc6/analysis/1403273691/ (https://www.virustotal.com/en/file/ac3a3175de710dddfed5afec2bf9de2c89197efbd8bd7772da0e4007c2f9efc6/analysis/1403273691/)
 also both sent by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)

hello
please be patient
wait for the launch of a next update
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 23, 2014, 08:29:15 PM
another file :
https://www.virustotal.com/en/file/6e8c457edbd95de57e4d7efbb2b03a01ad61eb8f3a52bde630cb5e71ffe58520/analysis/1403548082/ (https://www.virustotal.com/en/file/6e8c457edbd95de57e4d7efbb2b03a01ad61eb8f3a52bde630cb5e71ffe58520/analysis/1403548082/)
sent via http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on June 25, 2014, 11:18:22 PM
another file :
https://www.virustotal.com/en/file/6e8c457edbd95de57e4d7efbb2b03a01ad61eb8f3a52bde630cb5e71ffe58520/analysis/1403548082/ (https://www.virustotal.com/en/file/6e8c457edbd95de57e4d7efbb2b03a01ad61eb8f3a52bde630cb5e71ffe58520/analysis/1403548082/)
sent via http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)

was fixed in VPS update.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 26, 2014, 06:51:03 PM
another :
https://www.virustotal.com/en/file/6fed835c45e2c59c7d3660b113854d63c547ebfabc0ca181523939ced2dad50e/analysis/1403801362/ (https://www.virustotal.com/en/file/6fed835c45e2c59c7d3660b113854d63c547ebfabc0ca181523939ced2dad50e/analysis/1403801362/)
sent via http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on June 29, 2014, 04:56:16 PM
https://www.virustotal.com/en/file/08ffb38abd3b060d897f5c51726851dbe56def0a67523c37966c441e78e704a9/analysis/1404053633/

 also sent by  http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on June 30, 2014, 10:26:40 PM
https://www.virustotal.com/en/file/08ffb38abd3b060d897f5c51726851dbe56def0a67523c37966c441e78e704a9/analysis/1404053633/

 also sent by  http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)

Detection was fixed in next update.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on July 14, 2014, 01:32:48 PM
another one: https://www.virustotal.com/en/file/f2a2193c48777ad86db4665572d8a690009cdd433731b347cf53d9ac89adcbc8/analysis/1405337524/ (https://www.virustotal.com/en/file/f2a2193c48777ad86db4665572d8a690009cdd433731b347cf53d9ac89adcbc8/analysis/1405337524/)
sent also by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on July 17, 2014, 03:58:28 PM
another one: https://www.virustotal.com/en/file/f2a2193c48777ad86db4665572d8a690009cdd433731b347cf53d9ac89adcbc8/analysis/1405337524/ (https://www.virustotal.com/en/file/f2a2193c48777ad86db4665572d8a690009cdd433731b347cf53d9ac89adcbc8/analysis/1405337524/)
sent also by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)

the response of the analyst

Hello,
file with sha256 F2A2193C48777AD86DB4665572D8A690009CDD433731B347CF53D9AC89ADCBC8 is not in our DB -- this is because we don't store .zip files (we unpack them immediately). Upload to VT unpacked file and I can check then.

Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on July 24, 2014, 10:57:53 AM
problem is back https://www.virustotal.com/en/file/410b36ff8e24462ea1b197ea1be720e78b728a1d84ab5c0c9a5d6cb89008cd61/analysis/1406192515/ (https://www.virustotal.com/en/file/410b36ff8e24462ea1b197ea1be720e78b728a1d84ab5c0c9a5d6cb89008cd61/analysis/1406192515/)

also sent by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php) with this topic link
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on July 24, 2014, 10:38:41 PM
problem is back https://www.virustotal.com/en/file/410b36ff8e24462ea1b197ea1be720e78b728a1d84ab5c0c9a5d6cb89008cd61/analysis/1406192515/ (https://www.virustotal.com/en/file/410b36ff8e24462ea1b197ea1be720e78b728a1d84ab5c0c9a5d6cb89008cd61/analysis/1406192515/)

also sent by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php) with this topic link

delay to response
you are not receiving notification email 

Reporting for virus analyst 
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on July 26, 2014, 10:02:24 AM
for me seems fixed,thanks
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on July 26, 2014, 05:11:47 PM
for me seems fixed,thanks

thanks for confirmation. : )
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on July 29, 2014, 04:01:56 AM
for me seems fixed,thanks

the response was sent to the author of detection


Hello,
file 410b36ff8e24462ea1b197ea1be720e78b728a1d84ab5c0c9a5d6cb89008cd61 is not detected with latest VPS.

Milos

problem solved.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on August 05, 2014, 12:37:23 PM
Problems again:  https://www.virustotal.com/en/file/3c99dc45057f82eea725a47e1bd8985cf8bf6539f8be5c19f3137e8852bd1a95/analysis/1407234932/ (https://www.virustotal.com/en/file/3c99dc45057f82eea725a47e1bd8985cf8bf6539f8be5c19f3137e8852bd1a95/analysis/1407234932/)
also sent by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
thanks!
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: REDACTED on August 05, 2014, 09:28:05 PM
Avast reported Win32:Evo-gen [susp] and blocked download/execution of the Western Digital MyCloud installer, downloaded from WD:
 http://support.wd.com/product/download.asp?groupid=904&sid=207&lang=en

 I am unable to use my device.

I have also submitted Ticket Ref # : [[061514-8589471]] to Western Digital.

Is this a false positive, or an actual infection?

I have also attempted to submit a ticket with the file attached, but after unsuccessful several tries I gave up.

Thanks,
Frank


I have a similar issue when trying to install Todoist (https://en.todoist.com/windows), a well-known, task mgt app.  Reported to Todoist Support as well.

Anyone else experience this?  Believe it's a false positive but want to confirm prior to overriding at install.

Thanks...
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on August 05, 2014, 09:33:49 PM
Quote
Believe it's a false positive but want to confirm prior to overriding at install.
to do that is very easy ..... upload suspicious file(s) and test at one of these places  www.virustotal.com / www.metascan-online.com / www.jotti.org

like this
https://www.metascan-online.com/en/scanresult/file/094ba005f21643939c30338e96972865
https://www.virustotal.com/en/file/1147e57550246b80dee2b34db4ee584fae4ea61ec4ce0ddb017a0087b7250abe/analysis/1407267154/

First submission 2014-02-20 13:06:17 UTC ( 5 months, 2 weeks ago )

Quote
Copyright© Doist Ltd. 2013
Publisher Ist Productivity Ltd.
Product Todoist
File version 2.6.4.0
Description Todoist 2.6.4.0
Comments This installation was built with Inno Setup.
Signature verification  Signed file, verified signature
Signing date 8:01 AM 2/19/2014


so now report it to avast so that they can correct    ;)

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on August 07, 2014, 02:45:05 AM
Problems again:  https://www.virustotal.com/en/file/3c99dc45057f82eea725a47e1bd8985cf8bf6539f8be5c19f3137e8852bd1a95/analysis/1407234932/ (https://www.virustotal.com/en/file/3c99dc45057f82eea725a47e1bd8985cf8bf6539f8be5c19f3137e8852bd1a95/analysis/1407234932/)
also sent by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
thanks!

Reporting for virus analyst

If it was reported though contact form, than reporter will receive answer.

Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on August 13, 2014, 07:46:19 AM
Previous problem solved,now another file : https://www.virustotal.com/en/file/5ed3b04d10eca00317b27f20db95c837178d1816b95278e4477606cb214cf89a/analysis/1407908645/ (https://www.virustotal.com/en/file/5ed3b04d10eca00317b27f20db95c837178d1816b95278e4477606cb214cf89a/analysis/1407908645/)

also reported by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on August 13, 2014, 05:37:01 PM
Previous problem solved,now another file : https://www.virustotal.com/en/file/5ed3b04d10eca00317b27f20db95c837178d1816b95278e4477606cb214cf89a/analysis/1407908645/ (https://www.virustotal.com/en/file/5ed3b04d10eca00317b27f20db95c837178d1816b95278e4477606cb214cf89a/analysis/1407908645/)

also reported by http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)

If we were to check the forum regularly
would not possible  fix all problems
wait for the release of the next update
I hope it is fixed.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on August 28, 2014, 04:27:19 PM
new file : https://www.virustotal.com/en/file/047ee22a759dc7bf73dbfc26f2f745c4a70b021b001b79578c69fd26aef10810/analysis/1409235942/ (https://www.virustotal.com/en/file/047ee22a759dc7bf73dbfc26f2f745c4a70b021b001b79578c69fd26aef10810/analysis/1409235942/)
sent also by : http://www.avast.com/contact-form.php (http://www.avast.com/contact-form.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on September 01, 2014, 01:10:14 PM
still not fixed :(
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on September 01, 2014, 01:56:31 PM
still not fixed :(

is the reply.

Thanks for report. It will be fixed.
Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on November 12, 2014, 09:05:46 AM
new fp Win32:Evo-gen :
https://www.virustotal.com/en/file/84f1a1eb94001a28d84eda56cb400d9bff368dad8a0b2018fc198663886b96ff/analysis/1415779303/ (https://www.virustotal.com/en/file/84f1a1eb94001a28d84eda56cb400d9bff368dad8a0b2018fc198663886b96ff/analysis/1415779303/)

also sent by av interface

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 23, 2014, 07:56:09 AM
new fp Win32:Evo-gen :

https://www.virustotal.com/en/file/5f3b9c16ef535b17e8b3c13d0b0665b10f4a09deece36b5b69523f91fbf284bd/analysis/1419317571/ (https://www.virustotal.com/en/file/5f3b9c16ef535b17e8b3c13d0b0665b10f4a09deece36b5b69523f91fbf284bd/analysis/1419317571/)

https://www.virustotal.com/en/file/50f0bca2673907a23cdd55bfe468368b2f756e3a8690fcf31346aded07684988/analysis/1419317689/ (https://www.virustotal.com/en/file/50f0bca2673907a23cdd55bfe468368b2f756e3a8690fcf31346aded07684988/analysis/1419317689/)
also sent by av interface
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 24, 2014, 08:35:58 PM
please fix that!!
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on December 24, 2014, 09:28:33 PM
Report to avast lab here   https://support.avast.com

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 09, 2015, 06:19:02 PM
https://www.virustotal.com/en/file/3f90d9cb593140274b980f6d29a04f03706808fa48b3cc1a095a8a0fb1018dc3/analysis/1420823169/
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 22, 2015, 03:47:23 PM
https://www.virustotal.com/en/file/293520d6baf7a4961ef18717bb405f6707712ac64e8f64be22f7407a40cad516/analysis/1421937921/ (https://www.virustotal.com/en/file/293520d6baf7a4961ef18717bb405f6707712ac64e8f64be22f7407a40cad516/analysis/1421937921/)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on January 23, 2015, 01:47:57 AM
https://www.virustotal.com/en/file/3f90d9cb593140274b980f6d29a04f03706808fa48b3cc1a095a8a0fb1018dc3/analysis/1420823169/

https://www.virustotal.com/en/file/293520d6baf7a4961ef18717bb405f6707712ac64e8f64be22f7407a40cad516/analysis/1421937921/ (https://www.virustotal.com/en/file/293520d6baf7a4961ef18717bb405f6707712ac64e8f64be22f7407a40cad516/analysis/1421937921/)

Hello
I'm busy with some samples to be sent to detection of avast, as I have  not your files, VT (virus total)  distributed results are not feasible,I will attempt.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 27, 2015, 02:52:06 PM
not fixed,reported also to https://support.avast.com (https://support.avast.com)
https://www.virustotal.com/en/file/293520d6baf7a4961ef18717bb405f6707712ac64e8f64be22f7407a40cad516/analysis/1421937921/ (https://www.virustotal.com/en/file/293520d6baf7a4961ef18717bb405f6707712ac64e8f64be22f7407a40cad516/analysis/1421937921/)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on February 09, 2015, 10:43:34 AM
https://www.virustotal.com/en/file/986513a5b0a7bb7cf1c916cb5a2c39e89810d48886a1edee7b2568c5b9225048/analysis/1423474832/

another detection,reported also to https://support.avast.com

your detection algorithm for  Win32:Evo-gen is very buggy
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 11, 2015, 07:37:43 AM
again problems with this buggy detection
https://www.virustotal.com/ro/file/cedce8909da8037c31962300a30f3262bc9b3ad3c8cacb728a24a59ba5573909/analysis/1449815675/ (https://www.virustotal.com/ro/file/cedce8909da8037c31962300a30f3262bc9b3ad3c8cacb728a24a59ba5573909/analysis/1449815675/)
sent also by AV interface

For a while I could sent directly from webpage that kind of problems,now link page doesn't work (The page you were looking for doesn't exist) : https://support.avast.com/index.php (https://support.avast.com/index.php)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Eddy on December 11, 2015, 02:27:55 PM
Must be a problem on your end.
It is working for me without a problem.

https://www.avast.com/contact-form.php?subject=VIRUS-FILE
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 11, 2015, 08:36:01 PM
your link,works
thanks!
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 30, 2015, 10:55:35 AM
I'm sending files using https://www.avast.com/contact-form.php?subject=VIRUS-FILE (https://www.avast.com/contact-form.php?subject=VIRUS-FILE) and I get no answer/no email confirmation
I have again problems with :Evo-gen [Susp] - false positive
https://www.virustotal.com/en/file/c53570b28a370481cfa78d06a04db742da55eefbdab7f3f6bf0445431d3653d5/analysis/1451469211/ (https://www.virustotal.com/en/file/c53570b28a370481cfa78d06a04db742da55eefbdab7f3f6bf0445431d3653d5/analysis/1451469211/)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Milos on December 30, 2015, 12:08:44 PM
Hello,
thanks for notice, when did you submit the form?
FP will be fixed in next stream update.

Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Eddy on December 30, 2015, 01:04:05 PM
mrapi,

after submitting avast will only contact you if the need/want more information.

A automated confirmation by email could be a little improvement for the service.
Quote
Something like :
Thank you for sending us file x.y
We received it at : yyyymmdd hh:mm
Filesize : 12.3Mb
SHA-256 : 0x e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

We will analyze it and make changes in the detection when needed.
In case we need more information you will soon receive a request from us.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on December 30, 2015, 02:26:09 PM
Hi,I've submitted today
Hello,
thanks for notice, when did you submit the form?
FP will be fixed in next stream update.

Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 06, 2016, 10:50:59 AM
another FP : https://www.virustotal.com/en/file/98fec49374fb710b920e97e6c4448546de105018f63be7aa789f077b092762a4/analysis/1452073649/
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 14, 2016, 07:42:25 AM
another file: https://www.virustotal.com/en/file/107c8108c3fb1918f60e612455ce7de1f0dbf388a592fe6bfa5e4d615e1b341c/analysis/1452753606/ (https://www.virustotal.com/en/file/107c8108c3fb1918f60e612455ce7de1f0dbf388a592fe6bfa5e4d615e1b341c/analysis/1452753606/)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 22, 2016, 04:00:50 PM
another file,I've uploaded there it has 56 MB   : https://www.dropbox.com/s/m4v8om1ah4s8mkh/installAllnetSFXP.exe?dl=0 (https://www.dropbox.com/s/m4v8om1ah4s8mkh/installAllnetSFXP.exe?dl=0)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on January 22, 2016, 04:10:21 PM
Detection seems correct ... Riskware / PUP
https://www.virustotal.com/en/file/5b2f7cc9c8798da7f6a6ec7f154609b468dd95f7ced4a2296763e198f26b6e4a/analysis/1453475312/

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 22, 2016, 04:45:56 PM
Hi
We own that setup file,it includes PublicF1.exe  used for remote connections based on a password: http://www.freeremotesupport.net/i-need-remote-assistance (http://www.freeremotesupport.net/i-need-remote-assistance)

If I scan only that file I got it is just the same VT log as you got on setup
https://www.virustotal.com/en/file/9fb0e612bc0923f7dbe9decfe2aee85ccbcf578d50d91ab6cbfedaef05b256c3/analysis/1453476885/ (https://www.virustotal.com/en/file/9fb0e612bc0923f7dbe9decfe2aee85ccbcf578d50d91ab6cbfedaef05b256c3/analysis/1453476885/)
so detection is on this containing file but avast doesn't detect PublicF1.exe  as Win32:Evo-gen  it detects the setup file,that't the OLD BIG AVAST PROBLEM: FALSE POSITIVE EVEO-GEN !
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 25, 2016, 07:52:32 AM
Detection is still there,take a a look now:
https://www.virustotal.com/en/file/90af6b97db468aa5a2e7ab0cff9f3453d52bc298031e885872a2a4a748f2f713/analysis/1453704642/ (https://www.virustotal.com/en/file/90af6b97db468aa5a2e7ab0cff9f3453d52bc298031e885872a2a4a748f2f713/analysis/1453704642/)

file is there https://www.dropbox.com/s/m4v8om1ah4s8mkh/installAllnetSFXP.exe?dl=0
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 25, 2016, 05:15:45 PM
please fix that!

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on January 25, 2016, 05:30:32 PM
please fix that!
i assume you have reported it at the correct place

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 25, 2016, 05:45:18 PM
I have also a support ticket that says:  reported for 2 days and 9 hours

Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on January 26, 2016, 10:10:48 PM
Detection is still there,take a a look now:
https://www.virustotal.com/en/file/90af6b97db468aa5a2e7ab0cff9f3453d52bc298031e885872a2a4a748f2f713/analysis/1453704642/ (https://www.virustotal.com/en/file/90af6b97db468aa5a2e7ab0cff9f3453d52bc298031e885872a2a4a748f2f713/analysis/1453704642/)

Hello

Win32:Evo-gen [susp] is added to the result on VT when the comes application to malicious.
No detection of avast.The file is checked in Deepscreen it is created recently.
 
see attached
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on January 27, 2016, 08:12:16 AM
Milos fixed yesterday:
Hello,
OK, from the forum link I see that you have already created a ticket. It looks that our support have a long ticket queue so it will take some time to process it. Sorry for that. In meantime I fixed the detection which will be release in next stream update.
Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: jefferson sant on January 27, 2016, 10:09:14 PM
The problem was solved
it's nice to know it looking at this question  ; )
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on April 18, 2016, 07:41:55 AM
Another FP:  https://www.virustotal.com/en/file/133e5c17f3f4b3a5d0fdfef650b570e27fc42fa2377af54f9c1fc7cc295d50b1/analysis/1460957952/ (https://www.virustotal.com/en/file/133e5c17f3f4b3a5d0fdfef650b570e27fc42fa2377af54f9c1fc7cc295d50b1/analysis/1460957952/)
also sent by AV interface

EVERTHING CREATED WITH NSIS 3 RC1 seems to be ,YOUR ANTIVIRUS IS KILLING ME...
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Milos on April 18, 2016, 06:15:57 PM
Thanks, for the report. It will be fixed in next Stream update.

Milos
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on April 19, 2016, 11:06:09 AM
It will be nice for your antivirus team to find a permanent fix for that false positive,I'v started that topic on December 19, 2013 and posting over and over,that detection cause lots of problems to us,we are software developers and because of this FP we suggest to our clients to avoid Avast
you should fix that
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Asyn on April 19, 2016, 11:23:50 AM
...we are software developers...
-> File Whitelisting: https://www.avast.com/faq.php?article=AVKB229
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on April 19, 2016, 12:39:45 PM
Trust me I've sent the same file more than once  :)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Asyn on April 19, 2016, 12:43:58 PM
Trust me I've sent the same file more than once  :)
Well, the guys at the viruslab have to fix it then.
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on April 26, 2016, 06:28:00 PM
as expected,problem is back today:  https://www.virustotal.com/en/file/8ebe0e7bf2dcf0a06e1e9d2a28c29d77fa4ba543871658ce614792133bb9348a/analysis/1461687976/ (https://www.virustotal.com/en/file/8ebe0e7bf2dcf0a06e1e9d2a28c29d77fa4ba543871658ce614792133bb9348a/analysis/1461687976/)
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: mrapi on September 12, 2017, 10:29:19 AM
Hi
I have again lots of problems with that FP. where to send files?
Title: Re: Win32:Evo-gen [Susp] - false positive
Post by: Pondus on September 12, 2017, 10:32:34 AM
Hi
I have again lots of problems with that FP. where to send files?
Info is found in the sticky post at top in this forum section

Why dont you bookmark this  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438