I recently stumbled upon - what I think - is a false positive. I tried to run a Perl application using TK and suddenly I saw the message that the file tk.xs.dll was infected with a Trojan horse.
While having the window open I addressed this to AVG using their from last Sunday (so, a week ago) but so far I didn't get any feedback.
I then ran file on the website of VirusTotal.com and only 3 out of the 72 scanners used - Avast, AVG and Trellix - told me it has the Win64-Evo-gen [Trj] virus on board. All the others didn't find anything suspicious.
I want to know if that file is now really containing a thread or not. It's been around since 2001 and comes from ActiveState so I really doubt if it is infected. But since AVG didn't react on me sending the possibly infected file, I'm a bit in the dark now.
Unfortunately, I can't add the file to this post but it shouldn't be that hard to get a hand on it. In my case it's installed in the directory …\StrawberryPerl\cpan\build\Tk-804.036-0\blib\arch\auto\Tk\Tk.xs.dll.
Hello Geert,
Thank you for contacting AVG Community Support.
We understand that you are having concern about file marked as threat and want to check it. We'll certainly check and help you out.
If you are unsure about a file or false positive, you can scan it in Virus Total, or add the file to Quarantine and submit it to AVG Threat Labs.
Since you have already scan it via Virus Tiotal, I suggest you submit it to Threat Lab.
Quarantine is a safe place in AVG AntiVirus for storing potentially harmful files and completely isolating them from the rest of your operating system. Files in Quarantine cannot be accessed or run by any outside processes, software applications, or viruses.
You can send files to AVG Threat Labs for further analysis from Quarantine. Refer the following article to submit file for analysis:
Submit files to AVG Threat Labs (https://support.avg.com/SupportArticleView?l=en&urlName=Use-AVG-Antivirus-Quarantine&supportType=home#idt_030)
In most cases, AVG Threat Labs will process the file without sending a response to you.
When you submit application files to the AVG Threat Labs, a group of analysts review the software for malicious or unwanted activity. Applications that are both free from malware and meet our guidelines for application transparency can be whitelisted.
If determined clean, the submitted file is moved to our set of approved files to ensure it is no longer flagged as malicious.
AVG reserves the right to refuse to whitelist any application/website.
Regarding Win64-Evo-gen [Trj] file, I request you check if your virus definition is upto date and run a scan.
By default, AVG updates virus definitions automatically. However, AVG cannot perform the update if you are offline. To manually check for available updates, click the refresh icon above Last updated in the bottom-left corner of the AVG Internet Security application screen.
If you are still getting the same threat notification, please help us with the screenshot of the pop-up notification with threat details. You can post the screenshot here in your topic. Click on Answer & then click on the Image [mountain symbol] & follow the instructions.
Thank you and keep us updated.
Hello Geert,
Thank you for contacting AVG Community Support.
We understand that you are having concern about file marked as threat and want to check it. We'll certainly check and help you out.
If you are unsure about a file or false positive, you can scan it in Virus Total, or add the file to Quarantine and submit it to AVG Threat Labs.
Since you have already scan it via Virus Tiotal, I suggest you submit it to Threat Lab.
Quarantine is a safe place in AVG AntiVirus for storing potentially harmful files and completely isolating them from the rest of your operating system. Files in Quarantine cannot be accessed or run by any outside processes, software applications, or viruses.
You can send files to AVG Threat Labs for further analysis from Quarantine. Refer the following article to submit file for analysis:
Submit files to AVG Threat Labs (https://support.avg.com/SupportArticleView?l=en&urlName=Use-AVG-Antivirus-Quarantine&supportType=home#idt_030)
In most cases, AVG Threat Labs will process the file without sending a response to you.
When you submit application files to the AVG Threat Labs, a group of analysts review the software for malicious or unwanted activity. Applications that are both free from malware and meet our guidelines for application transparency can be whitelisted.
If determined clean, the submitted file is moved to our set of approved files to ensure it is no longer flagged as malicious.
AVG reserves the right to refuse to whitelist any application/website.
Regarding Win64-Evo-gen [Trj] file, I request you check if your virus definition is upto date and run a scan.
By default, AVG updates virus definitions automatically. However, AVG cannot perform the update if you are offline. To manually check for available updates, click the refresh icon above Last updated in the bottom-left corner of the AVG Internet Security application screen.
If you are still getting the same threat notification, please help us with the screenshot of the pop-up notification with threat details. You can post the screenshot here in your topic. Click on Answer & then click on the Image [mountain symbol] & follow the instructions.
Thank you and keep us updated.
Thank you for taking the time to write back to us and sharing the screenshot, Geert.
Our team will investigate this and will do needful.
If determined clean, the submitted file is moved to our set of approved files to ensure it is no longer flagged as malicious.
if you have more queries, do let us know.
Thank you and keep us updated.