Author Topic: Is this a false positive?  (Read 1689 times)

0 Members and 1 Guest are viewing this topic.

etpm

  • Guest
Is this a false positive?
« on: July 11, 2013, 02:26:27 AM »
I use Agent as my email and usenet program. A couple days ago Avast! said that the program, Agent.exe, is infected with win32:evo-gen [susp]. I have been running the Agent program for several years on the computer. I bought Avast! a couple months ago and it only now is telling me that the program is infected, and it has moved the program to the virus vault. So this means that the infection is new? Anyway, I went online to find out how to remove the virus, since Avast! won't, and after downloading MalwareBytes and updating it, two complete scans of my computer cannot find any type of virus or worm. Reading about the infection reported by Avast!, and how to get rid of it, I came across info in more than one place that said I should be able to find win32:evo-gen files in the registry and should delete them. But there are no files in the registry that relate to this virus. Is it possible that it is a false positive? How do I tell? Just use several anti-virus programs and if none report an infection assume that Avast! is reporting  false positive?
Thanks,
Eric

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Is this a false positive?
« Reply #1 on: July 11, 2013, 02:40:45 AM »
Quote
I went online to find out how to remove the virus, since Avast! won't,
you say avast have moved it to virus vault..... well, then avast have removed it

anf if it is infected and moved to chest, the there is nothing left for Malwarebytes to detect


Quote
win32:evo-gen [susp]
suspicious .....
if you think the detection is wrong, right click the file in chest and upload to avast lab as possible false detection

then wait a day or two, right click the file again and rescan it, if not infected you can restore it


how to use virus chest.    http://www.avast.com/faq.php?article=AVKB21


« Last Edit: July 11, 2013, 02:42:34 AM by Pondus »

etpm

  • Guest
Re: Is this a false positive?
« Reply #2 on: July 11, 2013, 05:54:12 PM »
Avast moved the whole program to the virus chest, not just the virus. I will try sending the program to Avast.
Thanks,
Eric