AEON 3.10 Antivirus False Positives req a fix ASAP Thanks

Discussion forum for Aeon users

Moderators: BTT, andy55, b.dwall, juxtiphi

User avatar
ozbeats
Posts: 199
Joined: Sun Jan 31, 2010 6:57 pm
Location: Adelaide, South Australia

AEON 3.10 Antivirus False Positives req a fix ASAP Thanks

Post by ozbeats »

Hi Andy and SS Team,

Just downloaded the AEON 3.10 Platinum release version and come up with a threat warning upon package installation that disables by blocking or quarantining these utility plugins dll's:

"Suspicious.Cloud.7.F" - suspected threat name or false positive

iTunes
Winamp
Realplayer
WMP x86 32bit version

removes these players ability to function, is restorable but I'd prefer you correct the packages on your side and run it past the correct checkmark parameters so it works fist-time for everyone....

Here are two screenshots of the issue and the associated threat or false positive requiring correction

http://screencast.com/t/kEAJneei

http://screencast.com/t/JLPPtfmE

Let me know if you need more info and please inform us when you have acknowledged these issues...and also of course when the installer has been corrected and recompliled it's availability from the download / updates section...

Thanks in Advance ...

Alf in Australia :D

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello ozbeats

I am guessing you are using Norton's AntiVirus program, this has happened in the past. I had the same problem Tuesday when I downloaded the program. I have already notified Andy about this problem.


Regards BTT

User avatar
ozbeats
Posts: 199
Joined: Sun Jan 31, 2010 6:57 pm
Location: Adelaide, South Australia

Post by ozbeats »

Yes BTT, I certainly am...... Norton 360 and have been for over 5 years.

Knowing myself like you that this has been a previous issue on occasions for the last two years...

I hope Andy and SS can add Norton Symantec False Positive checkpoints to their production checklist when they compile the installer packages so it doesn't continue to re-occur in future whatsoever...
just my thoughts, thanks...

Otherwise we can expect it re-occurring with upcoming new g-force and whitecap releases before the holidays too..... 8)

Alf

User avatar
andy55
Site Admin
Posts: 553
Joined: Sat May 01, 2004 4:38 pm
Contact:

Re: AEON 3.10 Antivirus False Positives req a fix ASAP Thank

Post by andy55 »

Hey everyone!

Yeah, this is definitely a false positive issue and hasn't been the first over the years. *sarcastic hat tip to Symantec*

I've submitted an official false positive report, but who knows when how timely their response will be (if at all!) for a small company such as SoundSpectrum.

You help will make it more likely for Symantec to take action, so please kindly go to the below link and submit a false positive report for 'When installing an application' via 'Auto-Protect'. Enter your info, "Suspicious.Cloud.7.F" for the detection field, skip the file fields, and in the 'Notes' section kindly make a statement that this is a false positive and the file can be downloaded at www.soundspectrum.com/aeon/serve.html

The Symantec false positive page is here:

https://submit.symantec.com/false_positive/

Thanks!
Andy
ozbeats wrote:Hi Andy and SS Team,

Just downloaded the AEON 3.10 Platinum release version and come up with a threat warning upon package installation that disables by blocking or quarantining these utility plugins dll's:

"Suspicious.Cloud.7.F" - suspected threat name or false positive

iTunes
Winamp
Realplayer
WMP x86 32bit version

removes these players ability to function, is restorable but I'd prefer you correct the packages on your side and run it past the correct checkmark parameters so it works fist-time for everyone....

Here are two screenshots of the issue and the associated threat or false positive requiring correction

http://screencast.com/t/kEAJneei

http://screencast.com/t/JLPPtfmE

Let me know if you need more info and please inform us when you have acknowledged these issues...and also of course when the installer has been corrected and recompliled it's availability from the download / updates section...

Thanks in Advance ...

Alf in Australia :D

User avatar
ozbeats
Posts: 199
Joined: Sun Jan 31, 2010 6:57 pm
Location: Adelaide, South Australia

Post by ozbeats »

Done... Thanks Andy for your detailed response....

On the email confirmation it says Symantec aim for a two business day response time (mon-fri) usually.

Just wasn't sure if it was something that could be corrected at your end or whether a resolution is dependant on a revision by the antivirus provider..

Fingers crossed... im on Skype now

p.s will there be a beta for g-force or whitecap before they are released

Cheers from Alf

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello All

I have received three emails from Symantec, each one informs me that they are unable to replicate the issue - so what now?


Regards BTT

jerohm
Senior Member
Posts: 421
Joined: Fri Jan 09, 2009 5:19 pm

RE: Suspicious.Cloud.7.F

Post by jerohm »

They obviously AREN'T trying hard enough. The SAME error also exists in the GF 5.0 Beta... I just set Norton to IGNORE the error on the file (WinAmp dll plugin I believe).

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello All

Have just downloaded a fresh copy of AEON from SS, and it installed without Norton playing silly *******.


Regards BTT
Last edited by BTT on Sun Dec 16, 2012 1:34 pm, edited 1 time in total.

User avatar
ozbeats
Posts: 199
Joined: Sun Jan 31, 2010 6:57 pm
Location: Adelaide, South Australia

Post by ozbeats »

Regarding the Norton Symantec false positive detections....

I had the same issue with Symantec BTT....
however now you've stated this issue has been corrected, I will remove the exclusion rules and try a fresh install-update too...

Thanks from Alf :D
BTT wrote:Hello All

I have received three emails from Symantec, each one informs me that they are unable to replicate the issue - so what now?


Regards BTT

User avatar
ozbeats
Posts: 199
Joined: Sun Jan 31, 2010 6:57 pm
Location: Adelaide, South Australia

Post by ozbeats »

My results...thanks BTT

All good, removed my exclusions and AEON installed without the auto-quarantine of plugin dll's....

However the exact same issue is still present with G-force 5 Beta A1 exe, and therefore removing these exclusions (set for AEON) re-enables detection of the g-force plugin dll's which are then quarantined...because of... Suspicious.Cloud.7.F - a suspected false positive i'd like SS to eradicate

So I had to reinstate my exclusions to allow g-force 5 (beta A1) to function completely

Excluded:

C:\Program Files (x86)\iTunes\Plug-Ins
C:\Program Files (x86)\Real\RealPlayer\Visualizations
C:\Program Files (x86)\Winamp\Plugins

Thanks, Alf

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello Alf
ozbeats wrote:however now you've stated this issue has been corrected, I will remove the exclusion rules and try a fresh install-update too...
I am NOT saying the issue has been corrected, all I am saying is that I downloaded a fresh copy of AEON and it installed without Norton reporting a false positive. Why this happens I don't have a clue.

Regards BTT

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello All

I have submitted a false positive report to Symantec reference the cloud 7f false positive in the G-Force 5.0 installer.


Regards BTT

User avatar
ozbeats
Posts: 199
Joined: Sun Jan 31, 2010 6:57 pm
Location: Adelaide, South Australia

Post by ozbeats »

No probs BTT, don't sweat. Cheers for your Norton submission
Yes, I understand the installer package (software version compiler) has corrected this issue in the current release version of AEON

(it's now present in the current G-force beta installation package instead)
With half our luck, it'll be fixed by the g-force 5 beta 1B release expected Tuesday

Don't really know why it occurs either, is it in the encoding or signatures or digital footprint certificates...?


Thanks for your time 8) Alf

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello All

Reference submission to Symantec regarding G-Force 5.0 Beta, they are unable to download the Beta for testing for the false positive as only registered users with a licence key can download the Beta. Guess we will have to wait until the full version is released (or follow Jerohm's suggestion).


Regards BTT

User avatar
BTT
Administrator
Posts: 2169
Joined: Sun Jun 20, 2010 9:34 pm
Location: United Kingdom

Post by BTT »

Hello All

The following relates to the false positive in G-Force 5.0 Beta:-

We are writing in relation to your submission through Symantec's on-line Security Risk / False Positive Dispute Submission form for your software being detected by Symantec Software. In light of further investigation and analysis Symantec is happy to remove this detection from within its products.

The updated detection will be distributed in the next set of virus definitions, available daily, or weekly via LiveUpdate, depending on Symantec product version, or daily from our website at


Regards BTT

Post Reply