<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010) in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/284301#M1167</link>
    <description>&lt;P&gt;I'm getting a similar false positive for&amp;nbsp;&lt;SPAN&gt;Microsoft Directory Services/ms-ds-smbv3 - &lt;/SPAN&gt;Virus/Win32.WGeneric.adwxyf. Occurs when attempting to copy Symantec Antivirus from a share.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 03:43:00 GMT</pubDate>
    <dc:creator>HenryFoss</dc:creator>
    <dc:date>2019-08-21T03:43:00Z</dc:date>
    <item>
      <title>False Positive: Virus/Win32.WGeneric.qqpeo(199010010)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/271698#M1098</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are getting several false positives for the following:&lt;/P&gt;&lt;P&gt;Hashes: MD5 -&amp;nbsp;&lt;/P&gt;&lt;P class="hash md5"&gt;522aaef14fd04b0cfbb92a5fb67f8daa&lt;/P&gt;&lt;P class="hash md5"&gt;c5d262166b7f4e9972d7e3e25df36d5c&lt;/P&gt;&lt;P class="hash md5"&gt;1910b1d2c94992fc21c6431a0eae1d78&lt;/P&gt;&lt;P class="hash md5"&gt;1ea5f8f65c07140d6fe639cf792a210c&lt;/P&gt;&lt;P class="hash md5"&gt;ffabe0604710b1070d044aa137465cd1&lt;/P&gt;&lt;P class="hash md5"&gt;48b696a3e96865a38cb4ee6c34163f19&lt;/P&gt;&lt;P class="hash md5"&gt;8d6abf4c351ee1d30ba40ddd61a2d60f&lt;/P&gt;&lt;P class="hash md5"&gt;b636ebe64a2905f61d659a854c5d5cf4&lt;/P&gt;&lt;P class="hash md5"&gt;e4de7fb09f13c7d0cb4d31083a1b6706&lt;/P&gt;&lt;P class="hash md5"&gt;ef002bca6c0f92debfa2d896a727ceaa&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/file/866aef3c8c9b4a7ccf6d6cad22a8b05d0ffed8e18590ec3d3e5b734d771363e3/detection" target="_blank" rel="noopener"&gt;https://www.virustotal.com/gui/file/866aef3c8c9b4a7ccf6d6cad22a8b05d0ffed8e18590ec3d3e5b734d771363e3/detection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 13:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/271698#M1098</guid>
      <dc:creator>Andrew_Gahan</dc:creator>
      <dc:date>2019-06-20T13:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/284301#M1167</link>
      <description>&lt;P&gt;I'm getting a similar false positive for&amp;nbsp;&lt;SPAN&gt;Microsoft Directory Services/ms-ds-smbv3 - &lt;/SPAN&gt;Virus/Win32.WGeneric.adwxyf. Occurs when attempting to copy Symantec Antivirus from a share.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 03:43:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/284301#M1167</guid>
      <dc:creator>HenryFoss</dc:creator>
      <dc:date>2019-08-21T03:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/284379#M1169</link>
      <description>&lt;P&gt;UPDATE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turns out there was a GPO to not permit logins to multiple sessions. This GPO called on a directory and copied some files locally. It wasn't until we started looking at the AV in addition to Palo we saw there was a "login.exe" being detected and flagged. After moving the user's OU and deleting the local copy, the GPO no logger applied and the alerts ceased.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luckily there was a "misc:" field in the Palo alert which eventually tipped us off.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best of luck!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 16:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/284379#M1169</guid>
      <dc:creator>Andrew_Gahan</dc:creator>
      <dc:date>2019-08-21T16:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/286598#M1184</link>
      <description>&lt;P&gt;In the future open a case with Palo Alto networks through your portal. THis is not the place to discuss your private network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a Palo Alto customer you have Support included and we could find and fix this much faster without exposing your files to the internet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 15:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-qqpeo-199010010/m-p/286598#M1184</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2019-09-04T15:54:17Z</dc:date>
    </item>
  </channel>
</rss>

