in fact, a popup just opened a few seconds ago on my desktop :
Avast antivirus (the software) had sent the installer file to the Avast company for extra analyses (and locked the file in quarantine meanwhile).
The popup says that the file is clean (good news).
The bad news is that it happen without asking anything.
Can’t believe it…
Maybe a particular binary pattern in the .exe triggered all that ?
We are unable to control what sort of heuristics trigger things. Unfortunately, if they published such data, it would be used maliciously.
We’ve submitted a couple of installer samples to Avast as known-good files. Let’s see if they incorporate that into their detection system. Hopefully they will eventually learn to trust our signature.