Author Topic: Avast Free is finding Win32:Evo-Gen [Susp] in Memory but not on Disk  (Read 2070 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I've been getting this on two machines since they upgraded to version 2015.10.2.2214.  It reports:

Process 1764 [explorer.exe], memory block 0x000000006EE30000, block size 659456 (ashShell.dll)   Medium    Threat: Win32:Evo-Gen [Susp]. 

It reports no problem with any files on disk, including the two mentioned in the message above.
I have run Kaspersky TDSSKiller and Norton Power Eraser, also without finding anything of consequence.
Both machines run fully patched Windows 7 Professional SP1.
Looks like a false positive to me, but I would like some advice before I ignore it.

Thanks


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37625
  • Not a avast user
Re: Avast Free is finding Win32:Evo-Gen [Susp] in Memory but not on Disk
« Reply #2 on: March 09, 2015, 08:00:13 AM »
Win32:Evo-Gen [Susp] = suspicious


Quote
Process 1764 [explorer.exe], memory block 0x000000006EE30000, block size 659456 (ashShell.dll)
have you changed any of the default scan settings?


REDACTED

  • Guest
Re: Avast Free is finding Win32:Evo-Gen [Susp] in Memory but not on Disk
« Reply #3 on: March 09, 2015, 08:33:42 AM »
I use a scan with the following settings:

Scan areas:
System Drive
Memory
Auto-start programs (all users)
Rootkits (full scan)

Scan all files: yes
Recognise file types by their: Content

I probably should point out that ashShell.dll is one of the files that downloaded with the avast upgrade.  There weren't any issues with the previous version and the warnings started immediately after the upgrade.  I've done a bit of digging and it seems that ashShell.dll supplies the scan option when you right-click on a file in explorer.  So that's why it is in explorer's memory space, but not why it is being reported as a possible virus.

Thanks


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37625
  • Not a avast user
Re: Avast Free is finding Win32:Evo-Gen [Susp] in Memory but not on Disk
« Reply #4 on: March 09, 2015, 08:41:39 AM »
Quote
Scan areas:
System Drive
Memory
Auto-start programs (all users)
Rootkits (full scan)
remove memory .... it give some weird results
detection in memory is (was) this forums second most frequently asked question ....lots of info if you search and find old topics

for a problem free operation, stay with default settings. avast team know what works   ;)




REDACTED

  • Guest
Re: Avast Free is finding Win32:Evo-Gen [Susp] in Memory but not on Disk
« Reply #5 on: March 09, 2015, 09:32:43 AM »
Thank-you for your assistance.
Bye