<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft Directory Services/ms-ds-smbv3 - Virus/Win32.WGeneric.yurld? in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/326085#M804</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We are see numerous alarms from our SIEM from our Palo Alto firewall. Here is a copy of a scrubbed log message below. When asking the user about their activity, they only RDP'ed into various servers from their laptop via the Globalprotect VPN for remote admin work and ran a batch file that re-maps drives. Additionally they noted browsing to \\&amp;lt;dcserver&amp;gt;\netlogon and that it seem to take long to enumerate directory. Also full AV endpoint scans show clean. Is this s false-positive?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 May 2020 08:19:42 GMT</pubDate>
    <dc:creator>NiganDong</dc:creator>
    <dc:date>2020-05-05T08:19:42Z</dc:date>
    <item>
      <title>Microsoft Directory Services/ms-ds-smbv3 - Virus/Win32.WGeneric.yurld?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/326085#M804</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are see numerous alarms from our SIEM from our Palo Alto firewall. Here is a copy of a scrubbed log message below. When asking the user about their activity, they only RDP'ed into various servers from their laptop via the Globalprotect VPN for remote admin work and ran a batch file that re-maps drives. Additionally they noted browsing to \\&amp;lt;dcserver&amp;gt;\netlogon and that it seem to take long to enumerate directory. Also full AV endpoint scans show clean. Is this s false-positive?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 08:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/326085#M804</guid>
      <dc:creator>NiganDong</dc:creator>
      <dc:date>2020-05-05T08:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Directory Services/ms-ds-smbv3 - Virus/Win32.WGeneric.yurld?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/326555#M807</link>
      <description>&lt;P&gt;Yes, that signature was disabled on&amp;nbsp;&lt;SPAN&gt;03/22/2019 14:30 PDT.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You must be running an outdated Antivirus or WildFire-Virus package.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please review what versions you're running and make sure your Dynamic Updates scheduler is properly set and that the firewall can reach updates.paloaltonetworks.com.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 23:22:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/326555#M807</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-05-06T23:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Directory Services/ms-ds-smbv3 - Virus/Win32.WGeneric.yurld?</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/343083#M926</link>
      <description>&lt;P&gt;Did you get a resolution to this?&amp;nbsp; We are experiencing a similar situation where ms-ds-smbv3 signature is being identified as a virus. We have all up to date Dynamic Content as well.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 17:46:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/microsoft-directory-services-ms-ds-smbv3-virus-win32-wgeneric/m-p/343083#M926</guid>
      <dc:creator>TerenceOyape</dc:creator>
      <dc:date>2020-08-10T17:46:28Z</dc:date>
    </item>
  </channel>
</rss>

