Author Topic: False positive Win32:Evo-gen [Susp]  (Read 5515 times)

0 Members and 1 Guest are viewing this topic.

Saso

  • Guest
False positive Win32:Evo-gen [Susp]
« on: March 10, 2013, 05:24:33 PM »
Hello I am from development team of uGet.
I want to report false positive.
When we start the latest version of uget, Avast detects a virus ("Win32: Evo-gen [Susp]").
After we checked the difference between two versions of uGet we realized that the problem occurs because of the recently
added strings in the program (used for language translation).
These are the links from where the last two versions of the program can be downloaded:
1.False-positive - http://www.uget.in/files/uGet-false-positive.exe
2.No False-positive - http://www.uget.in/files/uGet-no-false-positive.exe

Can you tell us why this problem occurs and how to avoid it?

Avast Free version 7.0.1474
« Last Edit: March 10, 2013, 05:27:57 PM by Saso »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: False positive Win32:Evo-gen [Susp]
« Reply #1 on: March 10, 2013, 05:57:05 PM »
Flagged because of file behavioral shield and the user can decide to run it undisturbed or block it as a potential suspicious file...
because the file does not as yet seem tio have collected a strong reputation among avast users
File a FP and send it to virus AT avast dot com, see https://www.virustotal.com/en/file/5b2714b1897a1ab3b25f93e2d9be4e47c7cfd4358c230b688d18b01e4023560e/analysis/1362934249/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Saso

  • Guest
Re: False positive Win32:Evo-gen [Susp]
« Reply #2 on: March 10, 2013, 07:31:16 PM »
Hello polonus,
Are you  from avast support ?
Both files have not a strong reputation among avast users.
The difference between the two files is only a few strings added.
There's no difference in the behavior of both versions but one is suspicious. Why is one of the files look suspicious?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: False positive Win32:Evo-gen [Susp]
« Reply #3 on: March 10, 2013, 07:42:46 PM »
No I am not with avast support, we users are all volunteers here on the avast forum.
But I just described what interaction  I experienced upon downloading from your link with the avast av solution active.....
This behavior of avast is while it is brand new to it and unknown, and under certain conditions avast will sandbox such executables first so the user can decide he has "the real McCoy.". The rest of the matter should be taken up with avast team members really, so file a FP report and they will act on the basis of that accordingly......

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!