Author Topic: Win32:Evo-gen [susp]  (Read 3428 times)

0 Members and 1 Guest are viewing this topic.

Woodwind

  • Guest
Win32:Evo-gen [susp]
« on: November 01, 2013, 11:07:06 AM »
Hi team

Getting this repeatedly no matter how much I clean with MBAM. Logs attached. Help would be very much appreciated!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Win32:Evo-gen [susp]
« Reply #1 on: November 01, 2013, 11:09:20 AM »
I've  notified Essexboy. He'll hopefully be here shortly
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Woodwind

  • Guest
Re: Win32:Evo-gen [susp]
« Reply #2 on: November 01, 2013, 11:11:03 AM »
Thanks alot Alan.

I've attached another log as well.
« Last Edit: November 01, 2013, 11:13:05 AM by Woodwind »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Win32:Evo-gen [susp]
« Reply #3 on: November 01, 2013, 11:13:05 AM »
OTL might be handy.. Can you run and attach that aswell?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Win32:Evo-gen [susp]
« Reply #4 on: November 01, 2013, 11:16:44 AM »
upload the adobe file to www.virustotal.com and test with 40+ malware scanners
post link to scan result here


Alternatives: www.metascan-online.com / www.jotti.org


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Win32:Evo-gen [susp]
« Reply #5 on: November 01, 2013, 11:19:09 AM »
Win32:Evo-gen [Susp]  = suspicious


You can upload files and report issues to avast  here : http://www.avast.com/contact-form.php  (select subject according to Your case)

You can use mail
send to virus@avast.com in a password protected zip file
mail subject:  False Positive / undetected sample (select subject according to your case)
zip password:  infected

or you can send files from avast chest
how to use the chest.    http://www.avast.com/faq.php?article=AVKB21


Woodwind

  • Guest
Re: Win32:Evo-gen [susp]
« Reply #6 on: November 01, 2013, 11:22:38 AM »
OTL attached.

I"ll try Pondus. Avast won't move it to chest. "Error: The request is not supported (50)

Woodwind

  • Guest

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Win32:Evo-gen [susp]
« Reply #8 on: November 01, 2013, 11:27:24 AM »
First submission 2009-02-22 11:03:51 UTC ( 4 years, 8 months ago )

use the guide above and send it to avast so they can correct it    ;)


Woodwind

  • Guest
Re: Win32:Evo-gen [susp]
« Reply #9 on: November 01, 2013, 12:00:03 PM »
Thank you Pondus. I've sent it in via the webform.
I also have a password protected ZIP if needed.

Cheers

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Evo-gen [susp]
« Reply #10 on: November 01, 2013, 03:11:28 PM »
Agree with the false positive, logs look clean