<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)] in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20892#M15256</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="active_link" href="https://live.paloaltonetworks.com/people/mwaters31" id="jive-518832,097,865,023,045,334" style="color: #555555; font-weight: bold; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: center; background-color: #f4f3f3;"&gt;mwaters31&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would open up a case with Support that includes the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Pcap of the threat&lt;/P&gt;&lt;P&gt;2) Output from the command &amp;gt;show system info&lt;/P&gt;&lt;P&gt;3) A snapshot of the threat via the threat log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'll investigate promptly and provide a bug fix if it's deemed as a false positive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Nov 2011 16:35:18 GMT</pubDate>
    <dc:creator>gswcowboy</dc:creator>
    <dc:date>2011-11-03T16:35:18Z</dc:date>
    <item>
      <title>Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20889#M15253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm hoping someone can help me with a threat detected by my PA500 (details below).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently found entries in my Threat logs suggesting an SSL-VPN user was malware compromised. Upon closer inspection, I cannot determine exactly the nature of the threat, nor how to detect/remove the threat from the client machine. I'm hoping this is not a false positive identifying a normal function as malware.(GoogleToolbarInstaller_updater_signed.exe)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not finding answers in Palo Alto's Threat database, nor in the Knowledgebase. But maybe someone here has some experience or insight regarding this threat? I'd appreciate some help, thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How real is this "virus"? (I can't find detailed descriptions on PaloAlto, let alone other sources)&lt;/P&gt;&lt;P&gt;How do I remove the infection?&lt;/P&gt;&lt;P&gt;Is this expected behavior from GoogleToolbarInstaller updater?&lt;/P&gt;&lt;P&gt;Why is this "bad"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="jiveNoBorder" style="width: 2402px; border: 0px solid rgb(0, 0, 204);"&gt;&lt;COL style="width: 48pt;" width="64" /&gt; &lt;COL style="width: 71pt;" width="95" /&gt; &lt;COL span="4" style="width: 48pt;" width="64" /&gt; &lt;COL style="width: 75pt;" width="100" /&gt; &lt;COL span="14" style="width: 48pt;" width="64" /&gt; &lt;COL style="width: 71pt;" width="95" /&gt; &lt;COL span="14" style="width: 48pt;" width="64" /&gt; &lt;TBODY&gt;&lt;TR style="height: 15pt;"&gt;&lt;TD height="20" style="height: 15pt; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Domain&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 71pt;" width="95"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Receive Time&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Serial #&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Type&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Threat/Content&amp;nbsp;&amp;nbsp; Type&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Config Version&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 75pt;" width="100"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Generate Time&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Source address&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Destination&amp;nbsp;&amp;nbsp; address&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;NAT Source IP&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;NAT Destination&amp;nbsp;&amp;nbsp; IP&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Rule&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Source User&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Destination User&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Application&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Virtual System&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Source Zone&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Destination Zone&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Inbound Interface&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Outbound&amp;nbsp;&amp;nbsp; Interface&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Log Action&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 71pt;" width="95"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Time Logged&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Session ID&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Repeat Count&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Source Port&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Destination Port&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;NAT Source Port&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;NAT Destination&amp;nbsp;&amp;nbsp; Port&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Flags&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;IP Protocol&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Action&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;URL&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Threat/Content&amp;nbsp;&amp;nbsp; Name&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Category&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Severity&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-left: medium none; width: 48pt;" width="64"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Direction&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt;"&gt;&lt;TD align="right" height="20" style="height: 15pt; border-top: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;08-07-11&amp;nbsp;&amp;nbsp; 06:30&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;0006C1xxxxxx&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;THREAT&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;virus&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;08-07-11&amp;nbsp;&amp;nbsp; 06:30&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;173.194.24.83&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;172.16.1.1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;173.194.24.83&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;71.180.xxx.xxx&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;rule1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;rmanik&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;web-browsing&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;vsys1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;L3-untrust&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;SSL-VPN&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;tunnel.1&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;ethernet1/5&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;08-07-11&amp;nbsp;&amp;nbsp; 06:30&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;50509&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;2&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;80&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;49797&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;80&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD align="right" style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;55650&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;0x400000&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;tcp&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;deny&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;GoogleToolbarInstaller_updater_signed.exe&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;Virus/Win32.slugin.iyz(2385375)&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;any&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;medium&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD style="border-top: medium none; border-left: medium none;"&gt;&lt;SPAN style="font-size: 8pt;"&gt;server-to-client&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Palo Alto Threat Database 3.1 yields the following description:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Virus/Win32.slugin.iyz (2385375)&lt;/P&gt;&lt;P&gt;Attack Name Worm/W32.generic.fklrm Description Threat ID 2385375&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The log detail is as follows:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;Log Details &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;Time&lt;BR /&gt;Generate Time: 2011/07/08 06:30:32&lt;BR /&gt;Receive Time: 2011/07/08 06:30:37&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;General&lt;BR /&gt;Session ID: 50509&lt;BR /&gt;Threat/Content Name: Virus/Win32.slugin.iyz&lt;BR /&gt;Threat/Content Type: virus&lt;BR /&gt;Action: deny &lt;BR /&gt;Severity: medium&lt;BR /&gt;Application: web-browsing &lt;BR /&gt;IP Protocol: tcp &lt;BR /&gt;Rule: rule1 &lt;BR /&gt;Log Action: &lt;BR /&gt;Category: any &lt;BR /&gt;Repeat Count 2&lt;BR /&gt;Virtual System: vsysl &lt;BR /&gt;Misc:&amp;nbsp; GoogleToolbarInstaller_updater_signed.exe&lt;BR /&gt;Device: 0006C1xxxxxx (myPa500Serial)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;Misc&lt;BR /&gt;Captive Portal: &lt;BR /&gt;Proxy Transaction: &lt;BR /&gt;Decrypted: &lt;BR /&gt;Packet Capture: &lt;BR /&gt;Direction: server-to-client&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;Source &lt;BR /&gt;Source User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Source address: 173.194.24.83 &lt;BR /&gt;Source Port: 80&lt;BR /&gt;Source Zone: L3-untrust &lt;BR /&gt;Inbound Interface: tunnel.1 &lt;BR /&gt;NAT Source IP 173.194.24.83 &lt;BR /&gt;NAT Source Port: 80 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;Destination&lt;BR /&gt;Destination User: rmanik&lt;BR /&gt;Destination address: 172.16.1.1&lt;BR /&gt;Destination Port: 49797&lt;BR /&gt;Destination Zone: SSL-VPN&lt;BR /&gt;Outbound Interface: ethernetl/5&lt;BR /&gt;NAT Destination IP: 71.180.xxx.xxx (myExternalPublicIp)&lt;BR /&gt;NAT Destination Port: 55650&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier; "&gt;Receive Time&amp;nbsp;&amp;nbsp; log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp; Application&amp;nbsp; Action Rule&amp;nbsp;&amp;nbsp; Bytes&amp;nbsp; Pkts Severity Category URL&lt;BR /&gt;07/08 06:30:37 threat&amp;nbsp; virus web-browsing deny&amp;nbsp;&amp;nbsp; rulel&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; medium&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; GoogleToolbarInstaller_updater_signed.exe&lt;BR /&gt;07/08 06:32:02 traffic end&amp;nbsp;&amp;nbsp; web-browsing allow&amp;nbsp; rule I 12,354 15&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My PA500:&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" id="TableGeneralInformation" width="340"&gt;&lt;TBODY id="BodyGeneralInformation"&gt;&lt;TR&gt;&lt;TD align="left"&gt;Software version&lt;/TD&gt;&lt;TD align="left"&gt;4.0.2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;SSL-VPN Client&lt;/TD&gt;&lt;TD align="left"&gt;1.3.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;GlobalProtect Client&lt;/TD&gt;&lt;TD align="left"&gt;0.0.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;Application version&lt;/TD&gt;&lt;TD align="left"&gt;255-1051&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;Threat version&lt;/TD&gt;&lt;TD align="left"&gt;254-1048&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;Antivirus version&lt;/TD&gt;&lt;TD align="left"&gt;515-673&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;URL Filtering version&lt;/TD&gt;&lt;TD align="left"&gt;3637&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="left"&gt;GlobalProtect datafile version&lt;/TD&gt;&lt;TD align="left"&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 14:53:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20889#M15253</guid>
      <dc:creator>Terina</dc:creator>
      <dc:date>2011-07-12T14:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20890#M15254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Terina - We've had several downloads of the GoogleToolbarInstaller_updater_signed.exe blocked by the same Threat ID 2385375.&amp;nbsp; Suspecting that it might be a false positive, I opened a case on July 5th.&amp;nbsp; It is still being researched.&amp;nbsp; -Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2011 17:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20890#M15254</guid>
      <dc:creator>cshep</dc:creator>
      <dc:date>2011-07-12T17:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20891#M15255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Curious if there has been any movement on this issue.&amp;nbsp; I am seeing this alot now on our PA500 classified as Trojan/Win32.patched.ocmj(2569370).&amp;nbsp; It seems to be associated with the Google-Update application.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 14:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20891#M15255</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-11-03T14:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20892#M15256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A class="active_link" href="https://live.paloaltonetworks.com/people/mwaters31" id="jive-518832,097,865,023,045,334" style="color: #555555; font-weight: bold; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: center; background-color: #f4f3f3;"&gt;mwaters31&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would open up a case with Support that includes the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Pcap of the threat&lt;/P&gt;&lt;P&gt;2) Output from the command &amp;gt;show system info&lt;/P&gt;&lt;P&gt;3) A snapshot of the threat via the threat log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'll investigate promptly and provide a bug fix if it's deemed as a false positive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Nov 2011 16:35:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20892#M15256</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-11-03T16:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20893#M15257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;+1.&amp;nbsp; I'd like to see the Threat Details include a MD5 Checksum so we may look at virustotal ourselves. Perhaps this will be possible with Wildfire?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Nov 2011 17:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20893#M15257</guid>
      <dc:creator>frank_henry</dc:creator>
      <dc:date>2011-11-10T17:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20894#M15258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello. I was wondering if there has been any updates to whether this is a legit threat or false positive?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 15:59:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20894#M15258</guid>
      <dc:creator>sschulman</dc:creator>
      <dc:date>2011-11-30T15:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Threat identification &amp; removal? [Virus/Win32.slugin.iyz(2385375)]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20895#M15259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the Tech Support working on the case I opened, a bug was found and was subsequently fixed in virus definition version 605.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2011 15:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-identification-removal-virus-win32-slugin-iyz-2385375/m-p/20895#M15259</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-12-01T15:34:06Z</dc:date>
    </item>
  </channel>
</rss>

