<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reporting False Positive from VirusTotal in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599412#M2556</link>
    <description>&lt;P&gt;Palo Alto no longer indicates our software as malware in VirusTotal. We have not yet received verification from our customer if they're unblocked, but we expect this to be the case very soon.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2024 09:29:09 GMT</pubDate>
    <dc:creator>thomas.jongepier</dc:creator>
    <dc:date>2024-10-03T09:29:09Z</dc:date>
    <item>
      <title>Reporting False Positive from VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599099#M2548</link>
      <description>&lt;P&gt;Dear Sir/Madam,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would like to report a false positive in your virus scanner software, which is reported on &lt;A href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.virustotal.com%2Fgui%2Ffile%2F46400b65266b8fe34f6f57c8ee2b8ada1154bf1aac0ca3a45569579f3b45e651%2Fdetection&amp;amp;data=05%7C02%7CThomas.Jongepier%403mensio.com%7Cdc5b98abb1154869656908dcd88e6328%7C6f1886789711484a8eb1f731475b6268%7C0%7C0%7C638623356510034031%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&amp;amp;sdata=wbOPTFXDIM4QduQeCY81qZlxwD7N8f2AlrjLAdYoWT4%3D&amp;amp;reserved=0" target="_blank"&gt;this page&lt;/A&gt;&amp;nbsp;on VirusTotal. The false positive in question is a small executable called CheckDotNetVersion.exe that we use during installation of our products. This executable attempts to find an existing .NET installation on the system, and if successful, runs the command&amp;nbsp;'dotnet --list-runtimes', and parses that command's output. The executable also dynamically loads kernel32.dll, as part of checking the system's architecture at runtime. The output of this executable is then used by our installer to decide if we need to install the .NET runtime or not. Upon request, the source code of this executable is available in case you want to inspect it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are &lt;A href="https://www.3mensio.com/" target="_blank"&gt;3mensio&lt;/A&gt;, a medical software company specialized in planning of cardiovascular procedures. Currently, our installation is reported by some of our customers as malicious software. We appreciate a swift processing of our request as it prevents some of our customers from performing medical care.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Thomas Jongepier&lt;/P&gt;
&lt;P&gt;Manager Research &amp;amp; Development&lt;/P&gt;
&lt;P&gt;3mensio Medical Imaging B.V.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 15:35:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599099#M2548</guid>
      <dc:creator>thomas.jongepier</dc:creator>
      <dc:date>2024-09-30T15:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting False Positive from VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599131#M2549</link>
      <description>&lt;P&gt;File has been submitted for review&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 21:20:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599131#M2549</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2024-09-30T21:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting False Positive from VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599217#M2551</link>
      <description>&lt;P&gt;file no longer deemed malware&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 19:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599217#M2551</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2024-10-01T19:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting False Positive from VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599412#M2556</link>
      <description>&lt;P&gt;Palo Alto no longer indicates our software as malware in VirusTotal. We have not yet received verification from our customer if they're unblocked, but we expect this to be the case very soon.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 09:29:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/reporting-false-positive-from-virustotal/m-p/599412#M2556</guid>
      <dc:creator>thomas.jongepier</dc:creator>
      <dc:date>2024-10-03T09:29:09Z</dc:date>
    </item>
  </channel>
</rss>

