Author Topic: False positive on a file detected as Win32:Evo-gen[Susp]  (Read 6523 times)

0 Members and 1 Guest are viewing this topic.

Offline Basu

  • Newbie
  • *
  • Posts: 4
False positive on a file detected as Win32:Evo-gen[Susp]
« on: November 30, 2017, 04:52:24 PM »
Avast antivirus detects a file (approx. 56 MB size) as Win32:Evo-gen[Susp]. However, a test conducted with VirusTotal come out as clean even for Avast scan via VirusTotal.

Here is the VirusTotal report: https://www.virustotal.com/en/file/5e299520ac3bb01ebfaa85caa7a7644ee7118b3906d8f485ba4adcc1f35e974c/analysis/

I request resolution of this false positive.

Thank you.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: False positive on a file detected as Win32:Evo-gen[Susp]
« Reply #1 on: November 30, 2017, 05:20:52 PM »
Win32:Evo-gen[Susp] = Suspicious


Quote
However, a test conducted with VirusTotal come out as clean even for Avast scan via VirusTotal.
Your screenshot show analysis date from yesterday.

Result today
https://www.virustotal.com/#/file/5e299520ac3bb01ebfaa85caa7a7644ee7118b3906d8f485ba4adcc1f35e974c/detection



If you think it is wrong, report it  >>  https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438


« Last Edit: November 30, 2017, 05:22:34 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Basu

  • Newbie
  • *
  • Posts: 4
Re: False positive on a file detected as Win32:Evo-gen[Susp]
« Reply #3 on: November 30, 2017, 08:54:23 PM »
@Pondus, @Polonus... Here is another rescan done a few minutes ago of the same file earlier submitted to VirusTotal. This time it is again back to my earlier results. Apparently, even the Avast scan via VirusTotal is not very consistent...  :)

https://www.virustotal.com/en/file/5e299520ac3bb01ebfaa85caa7a7644ee7118b3906d8f485ba4adcc1f35e974c/analysis/

The result is back to 5/66 with Avast not detecting and showing green. I am attaching another latest screenshot also.
« Last Edit: November 30, 2017, 09:04:08 PM by Basu »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: False positive on a file detected as Win32:Evo-gen[Susp]
« Reply #4 on: November 30, 2017, 09:18:27 PM »
I reported this post to avast team and @Milos was looking at it so detection may be removed now if it was a FP


Have you run a manual avast update?
Does your installed avast still detect?


Offline Basu

  • Newbie
  • *
  • Posts: 4
Re: False positive on a file detected as Win32:Evo-gen[Susp]
« Reply #5 on: November 30, 2017, 09:36:15 PM »
Thank you Pondus,

I just manually updated the definition file on one of my machines to the latest version 171130-6 dated 11/30/2017 11:39:43 pm... Eureka, it seems to be OK. Not detected this time.

I will now try it out on all my other machines which have Avast installations and report back.

Thank you once again.


Offline denics

  • Avast team
  • Full Member
  • *
  • Posts: 168
    • avast!
Re: False positive on a file detected as Win32:Evo-gen[Susp]
« Reply #6 on: November 30, 2017, 10:33:27 PM »
Hi, the false positive should be now fixed. Sorry for the inconvenience.
Denis Konopiský - avast! VirusLab | Android & Windows Malware | VPS Operations | Whitelisting

Offline Basu

  • Newbie
  • *
  • Posts: 4
Re: False positive on a file detected as Win32:Evo-gen[Susp]
« Reply #7 on: November 30, 2017, 11:05:25 PM »
Hi denics,

Thank you for a quick resolution... You guys rock.

Regards,
Basu