Some (even legitimate) programs explicit suspicious behaviour. And we at Avast are better safe then sorry, if it is “too suspicious”, we rather block it than let our users be infected. Furthermore, how do you define “legitimate program”? How do we know it is “legitimate” if we have no info about it?

There were 31 other files signed with the same digital signature. Not necessarily with the same filename, not necessarily submitted at the same time. Some might have arrived a year ago, for example.

Again, yes, but for a wrong reason. There are many malicious files (viruses, even) that update themselves. Just the fact that something “updates itself” doesn’t mean it is clean!