<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False Positive: Virus/Win32.WGeneric.yeksq in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250372#M883</link>
    <description>&lt;P&gt;File Hash: 44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &lt;A href="https://www.virustotal.com/en/file/44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3/analysis/1550490208/" target="_blank"&gt;https://www.virustotal.com/en/file/44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3/analysis/1550490208/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Virustotal verdict: 0/67&lt;/P&gt;&lt;P&gt;Description: Visma InSchool Primus client ver: W4.59.2&lt;/P&gt;</description>
    <pubDate>Mon, 18 Feb 2019 12:05:14 GMT</pubDate>
    <dc:creator>Salde</dc:creator>
    <dc:date>2019-02-18T12:05:14Z</dc:date>
    <item>
      <title>False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250372#M883</link>
      <description>&lt;P&gt;File Hash: 44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &lt;A href="https://www.virustotal.com/en/file/44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3/analysis/1550490208/" target="_blank"&gt;https://www.virustotal.com/en/file/44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3/analysis/1550490208/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Virustotal verdict: 0/67&lt;/P&gt;&lt;P&gt;Description: Visma InSchool Primus client ver: W4.59.2&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 12:05:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250372#M883</guid>
      <dc:creator>Salde</dc:creator>
      <dc:date>2019-02-18T12:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250430#M884</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This hash (&lt;SPAN&gt;44e94be969d812a907cc14e68c43280709b9be555e5c966e820af1eb6f7f48c3) is tied to a benign file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have asked our team to check signatrue&amp;nbsp;&amp;nbsp;Virus/Win32.WGeneric.yeksq&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 07:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250430#M884</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2019-02-19T07:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250468#M887</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This signature is been disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 17:45:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/250468#M887</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2019-02-19T17:45:39Z</dc:date>
    </item>
    <item>
      <title>Virus/Win32.WGeneric.aahwee</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/334007#M1480</link>
      <description>&lt;P&gt;Even we have recieved&amp;nbsp;Virus/Win32.WGeneric.aahwee signature&amp;nbsp;Threat ID: 2001455.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 09:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/334007#M1480</guid>
      <dc:creator>srinivaskarthik</dc:creator>
      <dc:date>2020-06-18T09:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/334015#M1481</link>
      <description>&lt;P&gt;Hi Himani,&lt;/P&gt;&lt;P&gt;Could you also check&amp;nbsp;Virus/Win32.WGeneric.aahwee signature, Threat ID: 2001455 as we are getting to many alerts&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 09:38:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/334015#M1481</guid>
      <dc:creator>srinivaskarthik</dc:creator>
      <dc:date>2020-06-18T09:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/334187#M1483</link>
      <description>&lt;P&gt;This forum is for non-customers reporting WildFire verdict FP's on VirusTotal.&lt;/P&gt;&lt;P&gt;If you have an AV signature triggering as an FP in your firewall, please open a Support case.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 20:53:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/334187#M1483</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2020-06-18T20:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/395894#M1829</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lately I have started seeing lots of&amp;nbsp; Threat Logs for Threat ID&amp;nbsp;406494039 which is for&amp;nbsp;Virus/Win32.WGeneric.bcqcxs as per&amp;nbsp;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&amp;nbsp;however the hashes provided in the signature/threat ID definition i have checked in Virus Total and other hash file repuation check , these are not reported any where so i have few question&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)If the hashes (below mentioned )corresponding to which this threat is checking are not malicious in any way then why the alert is triggering ?&lt;BR /&gt;&lt;BR /&gt;2) Since Palo alto is blocking these connection based on Threat ID and sending reset-both to client and server then why firewall resets the connection continuously i have seen 700+ logs&amp;nbsp; in less 11 hours so what this signifies some one was accessing the file continuously for 11 hours if not then why did firewall kept on sending reset-both for 11 hours ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would request you to please answer the above questions as soon as possible also i did not found a way to post a new question hence asking my questions here ..thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 21:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/395894#M1829</guid>
      <dc:creator>PratulSingh</dc:creator>
      <dc:date>2021-04-05T21:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/396353#M1830</link>
      <description>&lt;P&gt;Please provide an answer to the above questions ASAP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 15:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/396353#M1830</guid>
      <dc:creator>PratulSingh</dc:creator>
      <dc:date>2021-04-07T15:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/539347#M2370</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SECTION data-reactid=".0.1.1:$VbSpS"&gt;
&lt;DIV class="bootstrap-table"&gt;
&lt;DIV class="fixed-table-container"&gt;
&lt;DIV class="fixed-table-body"&gt;
&lt;P&gt;Can I get assistance on this false positive.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE id="antivirus-signatures" class="table table-bordered pan-grid table-hover" data-pagination="true" data-toggle="table" data-pagination-v-align="top" data-reactid=".0.1.1:$VbSpS.1"&gt;
&lt;TBODY data-reactid=".0.1.1:$VbSpS.1.1"&gt;
&lt;TR data-index="0" data-reactid=".0.1.1:$VbSpS.1.1.0"&gt;
&lt;TD data-reactid=".0.1.1:$VbSpS.1.1.0.2"&gt;
&lt;DIV data-reactid=".0.1.1:$VbSpS.1.1.0.2.0"&gt;
&lt;P class="hash sha256" data-reactid=".0.1.1:$VbSpS.1.1.0.2.0.0"&gt;9a27f17d859d7f60a26030c7a0ef3698ffa0ff5ff4230963e52ab79a6a4dacdf&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN&gt;Virus/Win32.WGeneric.dyafjk&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-reactid=".0.1.1:$VbSpS.1.1.0.0.1"&gt;Unique Threat ID: 575312775&lt;BR /&gt;&lt;SPAN&gt;Create Time: 2023-03-15 02:43:51 (UTC)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-reactid=".0.1.1:$VbSpS.1.1.0.0.1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Wed, 19 Apr 2023 11:52:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/539347#M2370</guid>
      <dc:creator>Salathiwe</dc:creator>
      <dc:date>2023-04-19T11:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/539430#M2371</link>
      <description>&lt;P&gt;please create a new post and include the information requested in the pinned post.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 23:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/539430#M2371</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-04-19T23:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/565625#M2418</link>
      <description>&lt;P&gt;Hello, this virus seems false positive. Its getting blocked at the firewall.&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Virus/Win32.WGeneric.atqfjb&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;a5bf3c0390b210abd3dacd1eb6d767b66962e0658470ac0b64ad281771ea9d0e&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 15:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/565625#M2418</guid>
      <dc:creator>shahzb</dc:creator>
      <dc:date>2023-11-14T15:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/565677#M2419</link>
      <description>&lt;P&gt;please create a new post&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 20:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/565677#M2419</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-11-14T20:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/575270#M2432</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;When I am trying to download&amp;nbsp;&lt;A href="https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer" target="_blank"&gt;https://marketplace.visualstudio.com/items?itemName=ritwickdey.LiveServer&lt;/A&gt;&amp;nbsp;this extension. &lt;SPAN&gt;Its getting blocked at the firewall via this signature&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Virus/Win32.WGeneric.atqfjb.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that false positive ?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 09:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/575270#M2432</guid>
      <dc:creator>tombombadil</dc:creator>
      <dc:date>2024-02-01T09:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive: Virus/Win32.WGeneric.yeksq</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/575551#M2433</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/263943"&gt;@tomber&lt;/a&gt;&amp;nbsp;You should open a Support ticket for this. This forum is mean to provide assistance to VirusTotal users that are&amp;nbsp;not Palo Alto Networks customers, regarding FP detections by Palo Alto Networks observed in VirusTotal detection reports, and not in firewalls.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 18:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-virus-win32-wgeneric-yeksq/m-p/575551#M2433</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2024-02-02T18:14:36Z</dc:date>
    </item>
  </channel>
</rss>

