Author Topic: Win32:Evo-gen [Susp]  (Read 6168 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Win32:Evo-gen [Susp]
« on: August 25, 2016, 04:03:42 PM »
Hello!  Everyday after an hour or two after I boot up my computer I will get a pop up saying they have quarantined a Win32:Evo-gen [Susp] file which normally is some random DLL file. I have scanned with Avast and Malwarebytes and cannot find anything.   Any suggestions?   

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Win32:Evo-gen [Susp]
« Reply #1 on: August 25, 2016, 04:07:58 PM »
Win32:Evo-gen [Susp] = Suspicious

what is the location of the file? full file path

do you have the full message avast give, maybe a screenshot of the popup message
If you have not rebooted computer, right click avast tray icon and select show last popup



« Last Edit: August 25, 2016, 04:10:30 PM by Pondus »

REDACTED

  • Guest
Re: Win32:Evo-gen [Susp]
« Reply #2 on: August 25, 2016, 04:46:16 PM »
Attached is the screen shot  C:\windows\temp\*  this file changes every day.
Process C:\winodws\syswow\svchost.exe

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Win32:Evo-gen [Susp]
« Reply #3 on: August 25, 2016, 04:52:37 PM »
do you have some sync stuff, like onedrive / gdrive / dropbox ?  if so try clear cache


Try empty your temp folders > TFC cleaner http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Win32:Evo-gen [Susp]
« Reply #4 on: August 25, 2016, 05:02:23 PM »
At first sight, given its location (a .dll file in temp) and random looking name, I would say avast is right to be suspicious of it. So for now (until further investigation) I would say not to Add the file to the scan exclusion list or Report the file as a false positive.

This needs further analysis by a malware removal specialist:
Go to this topic http://forum.avast.com/index.php?topic=53253.0 for information on Logs to assist in cleaning malware. Use the information about getting and using the tools and attach the logs here, not in the LOGS topic.

Since you have already run MBAM, you could attach its scan log to your next post.

Start with the Farbar Recovery Scan Tool (second one on the above link) and attach the two logs mentioned in the Information topic I gave the link for.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: Win32:Evo-gen [Susp]
« Reply #5 on: August 25, 2016, 07:57:33 PM »
Here are the logs.  Thanks for your help. 

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Win32:Evo-gen [Susp]
« Reply #6 on: August 26, 2016, 04:18:04 AM »

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Win32:Evo-gen [Susp]
« Reply #7 on: August 26, 2016, 02:05:58 PM »
Out of curiosity what is this fixing or changing? 

REDACTED

  • Guest
Re: Win32:Evo-gen [Susp]
« Reply #8 on: August 26, 2016, 06:14:13 PM »
Attached is the fixlog.  This time though right after I logged in I got the threat blocked, which normally takes time.

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Win32:Evo-gen [Susp]
« Reply #9 on: August 26, 2016, 10:03:22 PM »
The fixlist was trying to remove some unneeded 'trash' left in various places and close out some behind the scenes jobs that could be running.

I am beginning to suspect that this is a FP of some of the remote access software on this system.

1)  Can you upload the file(s) in question to virustotal.com and reply with links back to the scans there?

2)  Does the file(s) / warnings end if you temporarily disable TightVNC server / app?
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Win32:Evo-gen [Susp]
« Reply #10 on: August 29, 2016, 08:04:43 PM »
A few sites on virus total detects it as malware as you can see in the screen shot.   Today I have not received an alert yet but you might have something with the remote desktop as it seems to happen right around the first time I used VNC, RDP, or teamviewer.