Author Topic: False virus alert  (Read 1967 times)

0 Members and 1 Guest are viewing this topic.

Cassy TMW

  • Guest
False virus alert
« on: October 30, 2013, 06:41:31 PM »
Hello everyone,

I'm a real noob to such things, so I hope I'm choosing the right words:

I'm getting a false detection of http://download.evolonline.org/manaplus/brokenantivirus/libgcc_s_sjlj-1.dll and therefore can't open a program (a client for an open source MMORPG) or update/reinstall it.
The programmer of this client asked me to report to you, so can you please look at this and give me/us a short feedback?

Thank you very much in advance!  :)

Cassy

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: False virus alert
« Reply #1 on: October 30, 2013, 07:12:38 PM »
and what does the message say?


Cassy TMW

  • Guest
Re: False virus alert
« Reply #2 on: October 30, 2013, 07:20:24 PM »
Only that avast found a damaging website or file.
If you need more information, please just tell me which and maybe where I can find it.



This was when I tried to download  it again (therefore ...firefox.exe).
« Last Edit: October 30, 2013, 07:22:04 PM by Cassy TMW »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5710
  • Spartan Warrior
Re: False virus alert
« Reply #3 on: October 30, 2013, 07:23:23 PM »
Well, appears something is going on with your programmer's site, and not on your system:
http://urlquery.net/report.php?id=7315868
http://zulu.zscaler.com/submission/show/57411b45d56fcfa9ae4799cb612c89dc-1383157005
File here is detected by one a/v vendor.
https://www.virustotal.com/en/file/5ba372985be333f3d7576e6e8f53ee7c74da52453b4a22f5ed9517c37f1e335b/analysis/
Not blacklisted yet:
http://sitecheck.sucuri.net/results/download.evolonline.org/manaplus/brokenantivirus/libgcc_s_sjlj-1.dll

Screenshot of the toaster pop-up warning/block will help.

[EDIT:]  Not a well-known site according to WOT:  http://www.mywot.com/en/scorecard/download.evolonline.org?utm_source=addon&utm_content=contextmenu

Could you please change the link above to hxxp:// from the live one, http:?  This will help other users from possibly getting infected by unwittingly clicking the now live link.
« Last Edit: October 30, 2013, 07:32:41 PM by mchain »
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: False virus alert
« Reply #4 on: October 30, 2013, 07:26:51 PM »
Win32:Evo-gen [susp] = Suspicious



You can upload files and report issues to avast  lab here: http://www.avast.com/contact-form.php  (change subject according to Your case)

you can use mail

send to virus@avast.com in a password protected zip file
mail subject:  False Positive / undetected sample (select subject according to your case)
zip password:  infected

or you can send files from avast chest
how to use the chest.   http://www.avast.com/faq.php?article=AVKB21






Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: False virus alert
« Reply #5 on: October 30, 2013, 07:28:08 PM »
file is also very new at VT so not strange that avast say suspicious

First submission 2013-10-30 16:45:29 UTC ( 1 hour, 40 minutes ago )