<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VBS/Virus.invadesys.(253879) - Potential False Positive? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38107#M27911</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;False positives for threat ID 253879 have been confirmed. Fix targeted through AV release 1076.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Aug 2013 15:04:08 GMT</pubDate>
    <dc:creator>goku123</dc:creator>
    <dc:date>2013-08-09T15:04:08Z</dc:date>
    <item>
      <title>VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38106#M27910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently, on some of our clients we have been seeing the same threat / virus appear. The name is &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;VBS/Virus.invadesys. and the ID is &lt;/SPAN&gt;253879.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some interesting things to note...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The file-name is ALWAYS a bookmark file ending in .url&lt;/LI&gt;&lt;LI&gt;All of the files sound VERY generic.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Small sample of some URLs...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;"Guide Entertainment Network.url"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;"Monitor Tool 2008.url"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;"IE site on Microsoft.com.url"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;"&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;Windows Media Showcase.url"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;"Welcome to IE7.url"&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;Upon further investigation, it seems that these files come pre-packaged with IE7, as seen with one of the above URLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is, has anyone else seen an abundance of these alerts in the recent days?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 14:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38106#M27910</guid>
      <dc:creator>dciccone</dc:creator>
      <dc:date>2013-08-09T14:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38107#M27911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;False positives for threat ID 253879 have been confirmed. Fix targeted through AV release 1076.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 15:04:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38107#M27911</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-09T15:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38108#M27912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi achitwadgi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information. Any idea when this update will be available for download? I just checked on the PA devices, and it is not showing yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, where did you obtain this information? I cannot find it anywhere.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 15:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38108#M27912</guid>
      <dc:creator>dciccone</dc:creator>
      <dc:date>2013-08-09T15:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38109#M27913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, current AV version available is 1075. 1076 should go out later today.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 16:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38109#M27913</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-09T16:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38110#M27914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AV 1076 was just released, we are testing again with a couple of links. Will update this thread shortly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 18:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38110#M27914</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-09T18:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38111#M27915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AV 1076 is still triggering alerts on this threat id 253879 for URLs such as support.microsoft.com/kb/2123563.&lt;/P&gt;&lt;P&gt;This issue has been reopened with PAN threat team and is being further investigated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 20:38:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38111#M27915</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-09T20:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38112#M27916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Segoe UI'; font-size: 10pt;"&gt;A problem was discovered with the signature and this is being addressed with the combination of AV update today and the app+threat content update that is targeted for release on Tuesday Aug 13.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 22:24:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38112#M27916</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-09T22:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38113#M27917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the updates on this issue! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Aug 2013 18:45:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38113#M27917</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-11T18:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38114#M27918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have just received a report from a customer running 1078, that he has this false positive as well. Guess we are not quit there yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 13:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38114#M27918</guid>
      <dc:creator>urb</dc:creator>
      <dc:date>2013-08-14T13:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38115#M27919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please ensure that in addition to the latest AV package, you are also running apps+threat version 388 or newer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 14:29:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38115#M27919</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-14T14:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38116#M27920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running Apps and Threats version 388 antivirus version 1078 and am still reviving these alerts. Interestingly the threat ID and name are not present in the threat vault. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 18:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38116#M27920</guid>
      <dc:creator>jam1</dc:creator>
      <dc:date>2013-08-14T18:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: VBS/Virus.invadesys.(253879) - Potential False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38117#M27921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe the signature needs additional tuning. If you suspect this to be a false positive alert, can you please open a support case with the threat log screenshot &amp;amp; sample/url/threat pcap and 'show system info' output?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 18:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vbs-virus-invadesys-253879-potential-false-positive/m-p/38117#M27921</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-08-14T18:48:45Z</dc:date>
    </item>
  </channel>
</rss>

