<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False Positive AV block in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/false-positive-av-block/m-p/216075#M339</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;Not sure if this is under the correct category but here we go.&lt;BR /&gt;I have a false positive in my FWs, I have a file called Pv7_00_169SetupFull.exe which the FWs are detecting as Virus/Win32.WGeneric.qxdip&lt;/P&gt;&lt;P&gt;If I upload and scan the file with VirusTotal it gives all green lights: &lt;A href="https://www.virustotal.com/#/file/e36d3bb4f9eaff256ecd50f4a6875e41d65d12ef87d06bf7bde79874e989e259/detection" target="_blank"&gt;https://www.virustotal.com/#/file/e36d3bb4f9eaff256ecd50f4a6875e41d65d12ef87d06bf7bde79874e989e259/detection&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Thu, 31 May 2018 09:01:53 GMT</pubDate>
    <dc:creator>GOTRIDA</dc:creator>
    <dc:date>2018-05-31T09:01:53Z</dc:date>
    <item>
      <title>False Positive AV block</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/false-positive-av-block/m-p/216075#M339</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Not sure if this is under the correct category but here we go.&lt;BR /&gt;I have a false positive in my FWs, I have a file called Pv7_00_169SetupFull.exe which the FWs are detecting as Virus/Win32.WGeneric.qxdip&lt;/P&gt;&lt;P&gt;If I upload and scan the file with VirusTotal it gives all green lights: &lt;A href="https://www.virustotal.com/#/file/e36d3bb4f9eaff256ecd50f4a6875e41d65d12ef87d06bf7bde79874e989e259/detection" target="_blank"&gt;https://www.virustotal.com/#/file/e36d3bb4f9eaff256ecd50f4a6875e41d65d12ef87d06bf7bde79874e989e259/detection&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 09:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/false-positive-av-block/m-p/216075#M339</guid>
      <dc:creator>GOTRIDA</dc:creator>
      <dc:date>2018-05-31T09:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive AV block</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/false-positive-av-block/m-p/216127#M340</link>
      <description>&lt;P&gt;Sounds like a signature collision.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-is-a-signature-collision/ta-p/79086" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-is-a-signature-collision/ta-p/79086&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sometimes benign files collide with signatures generated for False Positives, and the collision can be resolved by fixing the FP.&lt;/P&gt;
&lt;P&gt;There are other instances where a file may be colliding with the signature of a true malware sample.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In that case the general recommendation will be to configure an Antivirus exception.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/create-threat-exceptions" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/create-threat-exceptions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In very particular situations, (where a signature for a true malware file causes a massive amount of collisions) we can work with PE files to make the signature more specific.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In any case, your issue should be worked through a Support case.&lt;/P&gt;
&lt;P&gt;Please open a case with Support.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 15:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/false-positive-av-block/m-p/216127#M340</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-05-31T15:58:59Z</dc:date>
    </item>
  </channel>
</rss>

