The Win32:Evo-gen [Susp] is as the [Susp] suffix is Suspicious and not necessarily considered 100%. I would suspect that the DLL would be being loaded into the System folder (and possibly why it is getting so much scrutiny) ?

So if a user knows that they downloaded it and installed it, they should be able to select an action from the alert/interactive window.

If they aren’t getting any option, it is being sent to the virus chest, it can also be sent directly to the virus labs from the virus chest.

Hopefully you will get the desired response from the support request from the Virus Labs that you submitted.