Installing flashplayer generates "Win32:Evo-gen [Susp]"/FileRepMalware warning

Hi,

got a problem when trying to install flashplayer on my system. PC just got a fresh Win7 64-bit install. (did that because I had a rootkit caused by a “faked” flash player update…).

I get a “Win32:Evo-gen [Susp]” warning when trying to install flashplayer using the installer from Adobe (avast blocks: http://fpdownload.macromedia.com/get/flashplayer/pdc/11.5.502.146/install_flash_player.exe) and the same warning when trying to install the IE version for the Avast statistics which is even more suprising (http://files.avast.com/files/sup/fl32.exe).
Using the firefox plugin installer gives me a “FileRepMalware” warning instead.

Looks like a false warning to me, but just want to make sure, as last time Flash got me the rootkit as mentioned above.

Using:
Avast 7.0.1474.
Firefox 18.0.1
Win 7 home premium 64-bit

There are a couple of posts about it already

if you have it in chest, right click and send to avast lab as false positive

Perhaps not the most helpful answer given how many people are hitting this article. Note that if you search on “Flash” and “Win32:Evo-gen” this is the only article that comes up. Also note that most people don’t get the executable in the virus chest, they just get it blocked by the Avast web shield. If there are other postings that people should be aware of it would be helpful to point them to those posting.

My solution is to disable the web shield and then run the Flash install.

Additionally, simply using a human/bot security challenge like this one by Solve Media is triggering the same response when it forwards to the URL containing the gibberish confirmation box string (to start the download) (indeed exactly like the confirmation following this post here):

http://www.lcpdfr.com/files/getdownload/978-lcpd-first-response/ (link is to verify to download a mod for the game GTA IV)

Nothing in the chest so can’t report false positives like that.

if you search in32:Evo-gen [Susp] you get lots of hits

http://forum.avast.com/index.php?topic=113984.0
http://forum.avast.com/index.php?topic=113978.msg889378#msg889378
http://forum.avast.com/index.php?topic=113984.msg889428#msg889428
http://forum.avast.com/index.php?topic=113991.msg889421#msg889421