Author Topic: File system shield: repeated win32:evo-gen false positives  (Read 1641 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
File system shield: repeated win32:evo-gen false positives
« on: June 29, 2016, 09:08:03 PM »
Hi, I'm a developer and just a couple days ago Avast has started giving me win32:evo-gen pop-ups on .exe installer files uploaded to my dropbox from my programmer, and then deletes it. Even if I hit the button telling to exclude the file, it still deletes it. And to top it off it doesn't even show up in the virus chest.

If i turn off "File System Shield" the file arrives fine, and I scan the file with no virus result at all. I also had my programmer download avast and scan entire system with no virus results found. So I believe it's a false positive. It's not a situation where I can submit a file to Avast for false positive report, as we're doing new builds all the time.

So I added the dropbox folder to "File System Shield" exclusion list, which now allows them to show up in dropbox, but now when I run the installer Avast still does some sort of blocking (was with the uninstall part of the package), so something still odd going on. Just to make sure I'm not dealing with real infection, I uploaded one of the installers to virustotal.com and it came back 100% clean.

I could turn off file system shield completely, but i don't really want to open myself up to any valid problems.

Also, keep in mind this just started happening a couple days ago. After it started happening I updated the Avast program files hoping it would fix it, but it didn't. I had been a while since I had updated the program itself, so doesn't seem like it would be directly related to the Avast update released on the 21st, unless it installed something other than virus definition files without me knowing.

Thanks for any help!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37601
  • Not a avast user
Re: File system shield: repeated win32:evo-gen false positives
« Reply #1 on: June 29, 2016, 10:13:43 PM »
WIN32:evo-gen [susp] = Suspicious  so not really a FP

How to report  >>  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Support: Avast File Whitelisting  >>  https://www.avast.com/faq.php?article=AVKB229#artTitle

« Last Edit: June 29, 2016, 10:17:23 PM by Pondus »