10-22-2021 07:49 AM - edited 10-22-2021 07:52 AM
Hi All,
We are being bombarded with retrospective quarantine failure alerts on multiple Endpoints for a file that is part of Adobe Creative Cloud - we believe it is a false positive but cannot fetch copy of the file to sandbox and confirm - anyone else having this issue?
0dc2a84e33199c78d83110a5f009fbd46f15726c9791f5aaee89ade44cf585b6
30a73ff6e72699f5a5daf1961504adc79aa5bda3fb80339e75e554301bb2e53a
Solved! Go to Solution.
10-23-2021 08:54 AM
This was a false positive and has been rectified. The files are no longer being marked as malicious. You might have to wait a while for the endpoint cache to expire.
10-22-2021 08:01 AM
10-22-2021 08:16 AM
This is happening at my company too.
10-22-2021 08:34 AM - edited 10-22-2021 08:36 AM
I am seeing this issue as well. Multiple detection events related to .aamdownload file extension, files located in temp. All files retro-quarantined failure due to them being temp and likely no longer available when the engine attempted to quarantine. Events are still actively happening.
10-22-2021 08:35 AM
Now with all the Adobe Creative Cloud detections and subsequent quarantine failures, PCs are starting to be isolated!
A month or two ago, didn't we get a bunch of Adobe Creative Cloud false positives that an email was sent out about?
10-22-2021 08:52 AM
You are correct @SReed2020 this did happen a couple of months ago as well. Super frustrating.
10-23-2021 08:54 AM
This was a false positive and has been rectified. The files are no longer being marked as malicious. You might have to wait a while for the endpoint cache to expire.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide