Win 32:Evo-gen [Susp] help - FP?

Hey,

So I know this has been a topic before but I am having this issue with Avast popping up an error saying blocked due to - Win 32:Evo-gen [Susp] help - now this is popping up on a WEB site not on a file downloading! I am trying to watch movies on SkyGo! Which you would think is a very safe site! plus really there is no really downloading going on as I am either watching live telly or streaming Movies!

Can someone please tell me how to fix this as Avast is now blocking it! :frowning: Not happy… It has only been happening for the last 2 days! I have run a virus check and noting!

Helllllppppp pleaseeee!!!

Hello,

If you could please attach a Screenshot and run the following programs.

http://forum.avast.com/index.php?topic=53253.0

The programs needed to be run (Please run in the list specified)

Adwcleaner/MBAM/OTL/AswMBR.

Attach the logs produced and report back. From there I will mnotify a remover.

Thanks,

Michael

Hey

Did all that!

Scan logs attached…

And the actual error that pops up!

I’ve notified TwinheadedEagle to assist you. From the looks of it, it’s not a website but a file attempting to launch. It also looks like you at once had a Rogue AV…

whats a rouge av when its at home?

And yes the file that might be trying to launch is SKY!!!

How come this has only just started to pop up now??? :frowning:

A Rogue AV is a Fake Anti-Virus. I could’ve mis-read the MBAM sig for it. And as for SkyGo, I don’t know much about it, I’d have to do a lot of digging, Looks legit but files can be faked easily. The ending on the file .dll (Driver) and .xap (Which is used for Phones and Silverlight stuff). I’d say Avast! flagged it for the Driver and silverlight file and .xap is not a common file type. For now please refrain from using SkyGo until it’s deemed clean.

If you wouldn’t mind, find the file and upload and test it here: www.virustotal.com. Report what it finds back.

Hey,

As I said there is no file!!!

And SkyGo is the online version of Sky as in the TV SKY or Sky broadband… as in www.sky.com or www.skygo.com

I just want to watch the Great British Bake off final! :frowning:

https://www.virustotal.com/en/url/03a90b5b9fd68dcf57b53de42e32b99e72dc7b0b6814b3ab25eb7a9e59e8e7ef/analysis/1383265419/

And

https://www.virustotal.com/en/url/0222339b47ed92fe8e1ef597dd951e8b86be148f1755a16c66eb0546999d9966/analysis/1383265479/

To avoid confusion I won’t try and explain it. Please wait for Twin to come help you. Once he’s arrived and reviewed your logs he can tell what’s happening and explain it too you.

I also scanned the error that origanally popped up and that came back clear…

http://go.sky.com/resources/web/silverlight/SkyPlayer.xap|SkyPlayer.Vod.dll

https://www.virustotal.com/en/url/7c8a3883d02a4176845ce1e9ec21b13286840a58da1d671d44ee37f5fbd595d2/analysis/1383265782/

I’m not a complete noob at tech I just can’t understand how a web site I have been using for months has suddenly become ‘suspicious’. I run regular scan with avast which is supposed to stop this… if its not what am I actually paying for? I update daily and all that… how can I stop Avast from scanning that page?

So please do try to explain… or will it get too technical for a girl like me??? :frowning:

It wasn’t meant to insult you. But given I don’t have thr training of Twin, Essex and all of the removers here. I’m not in a position to be offering explantions.

As for the question about Avast! and paying for it. Avast! will never have a 100% detection ratio. I use Avast! and Comodo on my system. Again, won’t block everything.

To stop the scanning of the page go to the Avast! UI (Right click the Icon) > Open Avast! User Interface > Settings (The little gear) > Antivirus > Exclusions > URL tab > And enter the URL.

From where I see it, the Objects are attempting to launch the site. In malware terms the files could be calling home to install more viruses.

I can get Polonus to do a more indepth analysis if you would like. If after that and Twin everything is clean you can report it as a FP to Avast! and have it Whitelisted globally.

Edit: I have to go to bed. It’s nearing 11PM here.

Yes please to all of that!

I tried to exclude the site but that didn’t work… and the error… it still won’t play the movies on Sky…

Nothing detected here: http://urlquery.net/report.php?id=7366099
Issue discussed here: http://forums.digitalspy.co.uk/showthread.php?s=f2cc685f0c0bb5b6bef08910e5dd6671&p=69516491#post69516491
I get a The requested URL /resources/web/silverlight/SkyPlayer.axp was not found on this server. Server redirect status
Clean: http://quttera.com/detailed_report/go.sky.com
Invalid URL
http://23.33.114.219/
The requested URL “/”, is invalid. ( N.B. this is the http title -note from polonus)
Reference #9.b4bb97d8.1383268079.3fbfccc
JSON info
{“country”: “United States”, “city”: “Cambridge”, “prefix”: “23.33.112.0/22”, “organization”: “BANDCON - Bandcon”, “latitude”: 42.3626, “ip”: “23.33.114.219”, “region”: “Massachusetts”, “hostname”: “a23-33-114-219.deploy.static.akamaitechnologies.com”, “asn”: “AS26769”, “longitude”: -71.0843}

pol

Hello, let’s check the system for bad stuff…

Please download GMER, AntiRootkit tool from the link below and save it to your Desktop:

Gmer download link
Note: file will be random named

Double-clicking to run GMER.

[*]Wait for initial scan to finish - if there is any query, click No;
[*]Click Scan button and wait until the full scan is complete;
[*]Click Save … - save the report to the Desktop (named Gmer );

Attach here Gmer logreports.

Then…

Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

GMer test log atteached

fbar test logs attached

Hi,

Download TDSSKiller and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Confirm “End user Licence Agreement” and “KSN Statement” dialog box by clicking on Accept button.

[*] Press Start Scan
[*] If Suspicious object is detected, the default action will be Skip, click on Continue.
[*] If Malicious objects are found, select Cure.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt

Please post the contents of that log in your next reply.

have any of the logs told you anything?

tdsskiller test log attached…

I really don’t think its my computer that is the problem here… its Avast… All these reports have come back clean…

its only Avast that is having the issues! My comp is running fine… Can’t you see if its Avast that’s having the issue?