Author Topic: NSIS False Positive: Win32:Evo-gen [Susp]  (Read 334 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
NSIS False Positive: Win32:Evo-gen [Susp]
« on: August 15, 2014, 11:02:12 PM »
My installer is being detected by your antivirus for no reason at all. My installer is built in NSIS

I provided examples of your false positives so you take steps to remove them.

I saw some other posts on here regarding NSIS false positives, so I think it's time you guys straighten it out.

Really frustrating because my users are becoming suspicious of my software for no fault of my own...

Download samples (provided many):
http://www.filedropper.com/avastfalsepositivesnsis
virustotals (some reason not showing on virustotal, but it's showing when I manually scan it)

https://www.virustotal.com/en/file/5ce2783a5e205d468b18e0573bc9667fe098895f1cbe744db700b423129a6693/analysis/
https://www.virustotal.com/en/file/8310fa25cd723e5cb10c598b3a4c65e2b4ec7dff5eb0912deb9790b96c51dbd0/analysis/
https://www.virustotal.com/en/file/e078415b08126118eb3de49c1e42262b015d2ac0de41910523bc8bf5951e9ab0/analysis/
https://www.virustotal.com/en/file/cffd3f795f41931c741212a6f44c102742f1576d176ae23cf534615d0c7e08d4/analysis/
https://www.virustotal.com/en/file/5b8eec3255962daa2ade600abad17236587e1ea980b815dd166e29aca9680313/analysis/
https://www.virustotal.com/en/file/fef4277a77cd5d817a23197170e860e232b36cdc8af00b162a568bfaeb46c9de/analysis/

Clearly Avast is the only AV to have this problem password: avastfp
=/

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: NSIS False Positive: Win32:Evo-gen [Susp]
« Reply #1 on: August 15, 2014, 11:49:23 PM »
Quote
Clearly Avast is the only AV to have this problem
not quite..... if you in VirusTotal click the Additional Information tab and scroll down to the bottom, you find a  "Symantec reputation Suspicious.Insight"
so not only avast is suspicious also Norton/Symantec

http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99

« Last Edit: August 15, 2014, 11:54:59 PM by Pondus »