Win32:Evo-gen [Susp] on NSIS is Getting Ridiculous...

Nope, the user above is 100% correct. Despite my detailed reports, Avast manages to do it again!

samples: https://www.sendspace.com/file/c1p7ie
pass: falsepositive

I don’t have time to do the virustotals, but I installed Avast in a virtual machine and it’s 100% tagging 5/6 of NSIS’s compression stubs as Evo-gen

I’ll be submitting this via your system, but people should be aware of how careless you guys are with detecting legitimate software

probably you will get an answer on Tuesday
wait for the next days

I am not do part software development
much less employees,through the ticket you can discuss this question.

all now is fixed in update VPS 140818-0

I have noticed a lot of *tmp files in the Virus Chest quarantined from C:\Windows\SoftwareDistribution\Download\ which I understand is the windows update folder, initially with this virus detection and I assume these are false positives as I have scanned again in the chest and they are now listed “no virus”. These files however, will not restore back to the original folder for some reason. Any suggestions as to why this is and if these files not being in their original position will cause problems?

Edit: I have now managed to restore all 92 files by re-creating the target folders

I see this problem is referred to in this thread:-

https://forum.avast.com/index.php?topic=153395.30

when a change in a system file or dll change (any even if it is insignificant)is inevitable that the system does not work the same way as it was before, is important that everything is put in local original.you can restore without problems,a window is shown just overwrite what is already there.problem has been solved.

Hi,
Avast tags NSIS again…
Samples: https://www.sendspace.com/file/m4gjw7
Pass: falsepositive

Virustotals (remember, evo-gen does not show on VT):
https://www.virustotal.com/en/file/5e4427b7a5d5b8372221e37def59c83ec31c706e26f162b75cbda681545e936a/analysis/1410588371/
https://www.virustotal.com/en/file/64d65dfc59cbf096fa3518f5741cc4b84b12333404967e04927e9216feebc6c5/analysis/1410588416/
https://www.virustotal.com/en/file/7a840c5282336a6d9b94a1d11091af0f30c6aaeb93650a34cf070284d60375a6/analysis/1410588455/
https://www.virustotal.com/en/file/7e5948070db3658d2ebea66697b2a2ecf867195ef3dafd20708f804ee576e0c3/analysis/1410588659/ (contacted clamav about their FP already)

Third time telling Avast of the NSIS false positives and they still continue … Maybe lack of communication ?

Anyway,
kind regards

Any application you make in Delphi or Dev C ++, or another programming language
have no other way but to wait for the avast 2015 version and see if things improve,avast detects with Evo-Gen [susp],wait during the week today not how to solve this problem.

problem was fixed in update VPS 140915-1
where will not detect by avast.