Win32:Evo-gen [Susp] Infekce zablokována

Infekce zablokována
URL hxxp://abitoftaste.altervista.org/morrowind/index2.php?option=downloads&no_comp=1&no_html=1&task=download&id=53&Itemid=50&-download-MMOG-Morrowind-Merged-Objects-Generator|Data Files\mmog.exe
Infection Win32:Evo-gen [Susp]
Relax, your avast! just saved you from a virus.
Protect yourself against other types of threats by upgrading now.

Just got this notice from the free version of Avast. The site seems an unlikely host for viruses (low profile modding site run by security-conscious programmer). Report has been uploaded to virustotal. Just wondering why Infekce zablokována is used instead of an english version, is this common for avast or should I be concerned?

Thanks!

Win32:Evo-gen [Susp] = Suspicious

VT scan of zipped file
https://www.virustotal.com/en/file/6e86253c58b232d5316ea7e6240f48cb5c8de24fb5b95659d50284a8f2405aab/analysis/1402789071/

unzipped
https://www.virustotal.com/en/file/ffdf5b25aa72b046d351a6db7805a488f0f0b28f858542aba811cd5e0cd62472/analysis/1402789204/

Good question! That is the same warning I’ve been getting a lot in the last two days – see my thread started today (bbexpert). By the way, when I called Avast, the person on the help line said that “Infekce zablokována” is the name of the malware on my computer. However, when I googled / translated it I learned that it’s really just saying “infection blocked” in Czech. You’d think that the Avast phone people would know that much…

However, I’m not suggesting that you do – or do not – have a virus on your computer. I’ll leave it to the Avast experts here to help you with that.

You would think that was something they would know about, especially since the virus is being specifically named elsewhere on the page! Hopefully someone knows why that’s coming up and will clue us in :slight_smile:

Going by the virustotal scans done by myself and Pondus it looks like it’s a false positive, but as you say that’s best left to experts to determine.

You'd think that the Avast phone people would know that much....
the phone people are not avast :-\

anyway, file is sendt avast lab for analysis

Thank you for your help :slight_smile: Do you happen to know as well why it says Infekce zablokována instead of Infection Blocked?

Do you happen to know as well why it says Infekce zablokována instead of Infection Blocked?
Nope....may be a bug in translation

If the phone people are not Avast, who are they? I called the help number on the Avast site, and let the phone answer person use one of those online log-in systems to look at my computer. But, she did not seem very knowledgeable at all and wanted to forward me to a more advanced “tech” so I would have to pay for more help.

Avast outsources its phone support to third party firm known for its shady practices scamming people. In the past, the firm was called iYogi, and Avast didn’t really care until the scams blew up in the press, but after the obligatory apologizing and saying they will look into it, I guess it is business as usual. Use the Avast forums for tech support.

I think the REAL problem about that…is it seems to come up when it is asking me if I want to pay the pay version…I keep hitting remind me later and it pops up ALL the time!!! All that says is infected files…so they make it look like it is infected to get us to pay for the pay per version!!!
NICE TRY
If that is not the way it is…then the support people would know that…well they do but they want to make it look like you are infected!!!\

Source…BF WORKS FOR THEM…and he is does the support thing…

I see he is still detected
I will try to expedite the process

submit the support ticket and attach the file

https://support.avast.com/Tickets/Submit

can take 6 days depending on the problem.

here is the answer.

Hello,

We tested your file. This problem will be correct in next update where It will not be takes as a virus.

Best regards,

Lukas Havel
Technical Support Specialist