Helpful ReplyVirus infection in X3 part2 and part3?

Author
SF_Green
Max Output Level: -62 dBFS
  • Total Posts : 1403
  • Joined: 2005/09/13 20:37:55
  • Location: San Francisco
  • Status: offline
2013/09/28 13:53:34 (permalink)

Virus infection in X3 part2 and part3?

Did anyone else get their downloads tagged with the Win32:Evo-gen virus?  Avast blocked my downloads on part2 and part3
 


AMD FX-8370, Gigabyte 990FXA-UD3,  Win7x64 SP1, 16Gb CorsairDDR3-1600, GeForce GTX 950 (390.65), SSD 525Gb (OS), SATA 3 & 1.5Tb, MOTU microlite, RME FireFace 800 (D 3.124, fw 2.77), UAD-2Q, Adam A7X, A-800 PRO, CC121
Cubase Pro 10.0.5, SonarPt-2017.10 (x64), Reason10.2, Live 10.0.5 Suite, Wavelab Elements 9.5.40, Komplete10Ult, POD Farm2.5, Omnisphere2.5, BFD3, Alesis QS7.1, Arturia BeatStep Pro, POD HD500, Alesis ControlPad, ARP Omni, many things with strings. GrSltz My Studio
#1
vladasyn
Max Output Level: -69 dBFS
  • Total Posts : 1092
  • Joined: 2005/02/05 00:33:23
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 13:56:21 (permalink)
Yes, it is old story- been doing it with every update- I have Norton. Disable it when installing and hope- it will not find it when turn back on.

https://soundcloud.com/vlada-astral 
http://vladasyn.wix.com/astral#
I am a female. Windows 8.1
Custom DAW Intel Core I7 3770K, 16 Gb memory, SSD+ 2 x 2 Gb storage. Presonus StudioLive 24.
  Multiple keyboards and modules, software synths.  
#2
SF_Green
Max Output Level: -62 dBFS
  • Total Posts : 1403
  • Joined: 2005/09/13 20:37:55
  • Location: San Francisco
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 14:01:33 (permalink)
Thanks vladasyn.  I remember some people reporting this in the past but I have not run into it before.  I reported it to Tech Support already so hopefully they will confirm that.
Cheers

AMD FX-8370, Gigabyte 990FXA-UD3,  Win7x64 SP1, 16Gb CorsairDDR3-1600, GeForce GTX 950 (390.65), SSD 525Gb (OS), SATA 3 & 1.5Tb, MOTU microlite, RME FireFace 800 (D 3.124, fw 2.77), UAD-2Q, Adam A7X, A-800 PRO, CC121
Cubase Pro 10.0.5, SonarPt-2017.10 (x64), Reason10.2, Live 10.0.5 Suite, Wavelab Elements 9.5.40, Komplete10Ult, POD Farm2.5, Omnisphere2.5, BFD3, Alesis QS7.1, Arturia BeatStep Pro, POD HD500, Alesis ControlPad, ARP Omni, many things with strings. GrSltz My Studio
#3
vladasyn
Max Output Level: -69 dBFS
  • Total Posts : 1092
  • Joined: 2005/02/05 00:33:23
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 14:08:37 (permalink)
It is not a virus- seen it before. I included my Plugins folders in to "Do not scan" list for antivirus. Unfortunately, Sonar updates installed in Program Files folder and it defeats the purpose to have antivirus if you put PF folder on exclude list. But there is a way to exclude folders and files in antiviruses. Otherwise- when you turn it back on, it may find your update or program and delete it.

https://soundcloud.com/vlada-astral 
http://vladasyn.wix.com/astral#
I am a female. Windows 8.1
Custom DAW Intel Core I7 3770K, 16 Gb memory, SSD+ 2 x 2 Gb storage. Presonus StudioLive 24.
  Multiple keyboards and modules, software synths.  
#4
Ryan Munnis [Cakewalk]
Administrator
  • Total Posts : 1067
  • Joined: 2009/11/01 10:28:44
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 14:45:29 (permalink) ☄ Helpfulby Noel Borthwick [Cakewalk] 2013/09/28 22:48:40
Yeah, definitely a false positive. This happens every launch. The files are brand new to the world and AV software tends to say "woah now!". We make sure to all run all the necessary virus scans before releasing to public and the system that holds the official installers is locked down (almost to an annoying degree at times) so that nothing is injected when we move things to the cloud servers. The only ill side effect you might catch from installing SONAR X3 is Recording Addiction. Is that a virus?

Ryan Munnis
Cakewalk
#5
chuckebaby
Max Output Level: 0 dBFS
  • Total Posts : 13146
  • Joined: 2011/01/04 14:55:28
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 15:09:55 (permalink)
first time upgrading SF ?   :)

Windows 8.1 X64 Sonar Platinum x64
Custom built: Asrock z97 1150 - Intel I7 4790k - 16GB corsair DDR3 1600 - PNY SSD 220GB
Focusrite Saffire 18I8 - Mackie Control
   
#6
SF_Green
Max Output Level: -62 dBFS
  • Total Posts : 1403
  • Joined: 2005/09/13 20:37:55
  • Location: San Francisco
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 15:38:07 (permalink)
chuckebaby
first time upgrading SF ?   :)




Hardly (been using Sonar since Sonar 4), it is the first time this has happened though.

AMD FX-8370, Gigabyte 990FXA-UD3,  Win7x64 SP1, 16Gb CorsairDDR3-1600, GeForce GTX 950 (390.65), SSD 525Gb (OS), SATA 3 & 1.5Tb, MOTU microlite, RME FireFace 800 (D 3.124, fw 2.77), UAD-2Q, Adam A7X, A-800 PRO, CC121
Cubase Pro 10.0.5, SonarPt-2017.10 (x64), Reason10.2, Live 10.0.5 Suite, Wavelab Elements 9.5.40, Komplete10Ult, POD Farm2.5, Omnisphere2.5, BFD3, Alesis QS7.1, Arturia BeatStep Pro, POD HD500, Alesis ControlPad, ARP Omni, many things with strings. GrSltz My Studio
#7
cparmerlee
Max Output Level: -67 dBFS
  • Total Posts : 1153
  • Joined: 2013/06/25 22:14:42
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 21:38:20 (permalink)
You can add an exclusion to the file system shield.  In my case the exclusion is
 
C:\Users\cparmerlee\Desktop\X3 downloads\*.*
 
"X3 downloads" is a folder on my desktop.

DAW: SONAR Platinum Audio I/F: Focusrite Scarlett 18i20 gen2
OS: Windows 10 64-bit CPU: Haswell 4790 4.0 GHz, 4 core, 8 thread  Memory: 16 GB      Video: GTX-760Ti
Storage: Sandisk SSD 500GB for active projects. ReadyNAS 20 TB for long-term storage

sonocrafters.com
#8
SuperG
Max Output Level: -63 dBFS
  • Total Posts : 1371
  • Joined: 2012/10/19 16:09:18
  • Location: Edgewood, NM
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 21:44:55 (permalink)
FWIW,
 
Norton AV is passing the files along just fine - even posting a toast saying so as the DL completes.
 
TIA

laudem Deo
#9
quest4success
Max Output Level: -88 dBFS
  • Total Posts : 104
  • Joined: 2009/10/22 09:51:20
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 21:45:32 (permalink)
I use Mcafee, never have to turn it off to install.  No problems with download.

Music, as seen, through the eyes of Larry Bynum aka Quest For Success (QFS). 
http://www.thequest4success.com/
Splat, Sweetwater Creation Station-Intel 6th Gen Core i5-6400 2.7GHz (3.3GHz Max Turbo Boost) 32GB RAM, 240GB SSD, 1TB Audio, 1TB Audio. Win 10 64-bit. Focusrite 6i6, Ozone 6, Komplete Kontrol 49, Komplete 12 Ultimate, Maschine Studio, MINILAB mkII, SparkLe, IK Uno Synth, Roland VT-3
#10
SF_Green
Max Output Level: -62 dBFS
  • Total Posts : 1403
  • Joined: 2005/09/13 20:37:55
  • Location: San Francisco
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 21:50:23 (permalink)
Yeah, like I said this was my first time.  I hit exclude and everything was ok after that.  I'm installed and working through the Melodyne tutorials now!
 
Thanks folks!
 

AMD FX-8370, Gigabyte 990FXA-UD3,  Win7x64 SP1, 16Gb CorsairDDR3-1600, GeForce GTX 950 (390.65), SSD 525Gb (OS), SATA 3 & 1.5Tb, MOTU microlite, RME FireFace 800 (D 3.124, fw 2.77), UAD-2Q, Adam A7X, A-800 PRO, CC121
Cubase Pro 10.0.5, SonarPt-2017.10 (x64), Reason10.2, Live 10.0.5 Suite, Wavelab Elements 9.5.40, Komplete10Ult, POD Farm2.5, Omnisphere2.5, BFD3, Alesis QS7.1, Arturia BeatStep Pro, POD HD500, Alesis ControlPad, ARP Omni, many things with strings. GrSltz My Studio
#11
cparmerlee
Max Output Level: -67 dBFS
  • Total Posts : 1153
  • Joined: 2013/06/25 22:14:42
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 21:58:44 (permalink)
SuperG
FWIW,
 
Norton AV is passing the files along just fine - even posting a toast saying so as the DL completes.
 
TIA


Well, it isn't necessarily a virtue to have an AV program that doesn't identify patterns that could be viruses.  I used Norton years ago and ditched it after viruses got through on multiple occasions, ruining my system.  I've never had anything get through Avast.  If the goal is to never be bothered by any detection messages, just run with no anti-virus program.

DAW: SONAR Platinum Audio I/F: Focusrite Scarlett 18i20 gen2
OS: Windows 10 64-bit CPU: Haswell 4790 4.0 GHz, 4 core, 8 thread  Memory: 16 GB      Video: GTX-760Ti
Storage: Sandisk SSD 500GB for active projects. ReadyNAS 20 TB for long-term storage

sonocrafters.com
#12
SuperG
Max Output Level: -63 dBFS
  • Total Posts : 1371
  • Joined: 2012/10/19 16:09:18
  • Location: Edgewood, NM
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 22:32:30 (permalink)
I haven't had any problems with Norton, and I've been using it for over 10 years. There's just nothing in the file to alert on. My guess is that AVAST may be making the generic assumption that an .exe file, especially one with a boatload of (compressed) attached data may contain a virus. If that's the case, it would be better to internally uncompress and scan it - but that would slow performance. Not sure how Norton manages it.
 
Proof in the pudding would be to have Avast scan all the extracted files - if it passes, than indeed it has not scanned the internal files (uncompressed).

laudem Deo
#13
cparmerlee
Max Output Level: -67 dBFS
  • Total Posts : 1153
  • Joined: 2013/06/25 22:14:42
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 22:39:21 (permalink)
SuperG
I haven't had any problems with Norton, and I've been using it for over 10 years. There's just nothing in the file to alert on. My guess is that AVAST may be making the generic assumption that an .exe file, especially one with a boatload of (compressed) attached data may contain a virus. If that's the case, it would be better to internally uncompress and scan it - but that would slow performance. Not sure how Norton manages it.
 
Proof in the pudding would be to have Avast scan all the extracted files - if it passes, than indeed it has not scanned the internal files (uncompressed).


I think Avast is considerably more advanced than what you describe.  I haven't had any false positives for at least 6 months, until these downloads of X3.  There is clearly something peculiar in those downloads that is making Avast very unhappy.  Sometimes random patterns could match virus profiles, but evidently this is something that happens on each release.  I don't recall it happening when I installed X2.
 
The only two AV programs I trust at this stage are Avast and NOD.

DAW: SONAR Platinum Audio I/F: Focusrite Scarlett 18i20 gen2
OS: Windows 10 64-bit CPU: Haswell 4790 4.0 GHz, 4 core, 8 thread  Memory: 16 GB      Video: GTX-760Ti
Storage: Sandisk SSD 500GB for active projects. ReadyNAS 20 TB for long-term storage

sonocrafters.com
#14
Sycraft
Max Output Level: -73 dBFS
  • Total Posts : 871
  • Joined: 2012/05/04 21:06:10
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 22:42:19 (permalink)
NOD32 does not show any viruses in X3.
#15
SuperG
Max Output Level: -63 dBFS
  • Total Posts : 1371
  • Joined: 2012/10/19 16:09:18
  • Location: Edgewood, NM
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 23:12:38 (permalink)
It's got to be firing off based on hueristics, not on an actual signature match. Even Norton will do that - but it does pop-up and tell you that it's based on that - not a signature match, and that's the cue to use what you know about that file in making a choice.
 
To be sure, I'd much rather have it pop-off than have it miss...
 

laudem Deo
#16
SuperG
Max Output Level: -63 dBFS
  • Total Posts : 1371
  • Joined: 2012/10/19 16:09:18
  • Location: Edgewood, NM
  • Status: offline
Re: Virus infection in X3 part2 and part3? 2013/09/28 23:12:38 (permalink)
It's got to be firing off based on hueristics, not on an actual signature match. Even Norton will do that - but it does pop-up and tell you that it's based on that - not a signature match, and that's the cue to use what you know about that file in making a choice.
 
To be sure, I'd much rather have it pop-off than have it miss...
 

laudem Deo
#17
Jump to:
© 2024 APG vNext Commercial Version 5.1