<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive Removal Request Winflector in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237348#M789</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file&amp;nbsp;"wfsetup-3964.exe"&amp;nbsp; sha256sum is&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;2b57bd2885eb1c505fed8c14c41dd7b1d6cac4e7d4029d801ce5bbc6110e8c5b. I&lt;/SPAN&gt;&amp;nbsp;checked this is benign.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;The hash with VT link doesn't match.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN&gt;ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Thanks&lt;/P&gt;&lt;P class="p1"&gt;Himani&lt;/P&gt;</description>
    <pubDate>Fri, 26 Oct 2018 19:30:45 GMT</pubDate>
    <dc:creator>hisingh</dc:creator>
    <dc:date>2018-10-26T19:30:45Z</dc:date>
    <item>
      <title>False Positive Removal Request Winflector</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237250#M781</link>
      <description>&lt;DIV class="lia-message-heading lia-component-message-header"&gt;&lt;DIV class="lia-quilt-row lia-quilt-row-standard"&gt;&lt;DIV class="lia-quilt-column lia-quilt-column-20 lia-quilt-column-left"&gt;&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;&lt;DIV class="lia-message-subject"&gt;False-positive submission&lt;/DIV&gt;&lt;DIV class="lia-message-subject"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-subject"&gt;Hi research team,&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-body"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PaloAlto false-positive detected,&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Cylance and VBA32 false-positive detected&lt;/SPAN&gt; the&amp;nbsp;application (wfserver.exe).&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.virustotal.com/#/file/ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644/detection" href="https://www.virustotal.com/#/file/ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644/detection" target="_blank"&gt;https://www.virustotal.com/#/file/ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The appliaction is a part of the installer:&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.virustotal.com/#/file/2b57bd2885eb1c505fed8c14c41dd7b1d6cac4e7d4029d801ce5bbc6110e8c5b/detection" href="https://www.virustotal.com/#/file/2b57bd2885eb1c505fed8c14c41dd7b1d6cac4e7d4029d801ce5bbc6110e8c5b/detection" target="_blank"&gt;https://www.virustotal.com/#/file/2b57bd2885eb1c505fed8c14c41dd7b1d6cac4e7d4029d801ce5bbc6110e8c5b/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please clean paloAlto false-positive detection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file/installer can be downloaded from:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.winflector.com/store/free-version/index/id/388" href="https://www.winflector.com/store/free-version/index/id/388" target="_blank"&gt;https://www.winflector.com/store/free-version/index/id/388&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would appriciate your quick help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rafal&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 26 Oct 2018 08:15:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237250#M781</guid>
      <dc:creator>dziekan</dc:creator>
      <dc:date>2018-10-26T08:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request Winflector</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237335#M787</link>
      <description>&lt;P&gt;Hi Dziekan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am checking on the sample and I will update the result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 18:31:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237335#M787</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-26T18:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request Winflector</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237348#M789</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file&amp;nbsp;"wfsetup-3964.exe"&amp;nbsp; sha256sum is&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;2b57bd2885eb1c505fed8c14c41dd7b1d6cac4e7d4029d801ce5bbc6110e8c5b. I&lt;/SPAN&gt;&amp;nbsp;checked this is benign.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;The hash with VT link doesn't match.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN&gt;ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Thanks&lt;/P&gt;&lt;P class="p1"&gt;Himani&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 19:30:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237348#M789</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-26T19:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request Winflector</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237373#M792</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The link for wfserver.exe file extracted from the installer.&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.winflector.com/wfserver.exe" href="https://www.winflector.com/wfserver.exe" target="_self"&gt;https://www.winflector.com/wfserver.exe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and VT link:&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.virustotal.com/#/file/ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644/detection" href="https://www.virustotal.com/#/file/ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644/detection" target="_self"&gt;https://www.virustotal.com/#/file/ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rafal&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 20:19:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237373#M792</guid>
      <dc:creator>dziekan</dc:creator>
      <dc:date>2018-10-26T20:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request Winflector</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237397#M793</link>
      <description>&lt;P&gt;Reported&amp;nbsp;ec36883157a62423c80c5ff315ede3bc81fa6ee3ac4c6931d797b8f744c9a644 for manual verdict re-evaluation.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 21:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237397#M793</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-10-26T21:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request Winflector</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237681#M798</link>
      <description>&lt;P&gt;Verdict has been changed to benign.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 20:18:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-winflector/m-p/237681#M798</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-10-29T20:18:49Z</dc:date>
    </item>
  </channel>
</rss>

