<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rogue/Fake Antivirus Malware detection? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41380#M30413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was wondering if there is any way to detect the Rogue/Fake Antivirus Malware that is making its way around the internet?&lt;/P&gt;&lt;P&gt;A couple in paticular are Internet Security 2010, Antivirus Live and Advanced Virus Remover.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Apr 2011 18:35:05 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-04-21T18:35:05Z</dc:date>
    <item>
      <title>Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41380#M30413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was wondering if there is any way to detect the Rogue/Fake Antivirus Malware that is making its way around the internet?&lt;/P&gt;&lt;P&gt;A couple in paticular are Internet Security 2010, Antivirus Live and Advanced Virus Remover.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Apr 2011 18:35:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41380#M30413</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-04-21T18:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41381#M30414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Along with our standard AV and Spyware signatures and known-malware URL categories, we have introduced a new "drive-by download protection" feature in PAN-OS 4.0.&amp;nbsp; Basically this gives you the capability of setting a "continue" action on a file-blocking profile.&amp;nbsp; For instance, you can set all executable downloads as "continue".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This keeps malicious web pages from automatically downloading and installing fake antivirus and malware detection programs when users inadvertently hit the page.&amp;nbsp; Instead they will get a warning page pop up that you can customize.&amp;nbsp; If the file really is legitimate, the user can continue the download at their choice and the session will be logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Apr 2011 15:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41381#M30414</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-04-22T15:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41382#M30415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri;"&gt;Specific threats aside the only way we will detect any malicious traffic is if it traverses the properly licensed Firewall.&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;Of course the threats must also be identified and a signature be created that we can match. You can also detect via a TAP interface but this will not allow for anything beyond reporting.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Apr 2011 18:09:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41382#M30415</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-04-22T18:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41383#M30416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: times new roman,times;"&gt;Having read this thread, I'm not sure the question asked was answered.&amp;nbsp; So let me re-ask the orginal question another way.&amp;nbsp; Do PA's malware or threat filters have signatures for the Rogue/Fake AV malware that continues to circle the Internet?&amp;nbsp; I'm guessing not because as recent as two weeks ago, one of our staff hit a site that infected her work machine with fake AV malware while she was in the office.&amp;nbsp; The firewall that handled that user's traffic at the time was running the 4.08 code at that time.&lt;/SPAN&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 15:16:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41383#M30416</guid>
      <dc:creator>carlboyer</dc:creator>
      <dc:date>2012-03-12T15:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41384#M30417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The WildFire feature in 4.1 code should detect these types of malware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 15:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41384#M30417</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2012-03-12T15:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41385#M30418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 19:45:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41385#M30418</guid>
      <dc:creator>carlboyer</dc:creator>
      <dc:date>2012-03-12T19:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41386#M30419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;However it will miss the first detection and if these fake AV sites regenerate their exe files (to avoid detection from signaturebased AV's) Wildfire wont help (since Wildfire will only get a hit if the particular executable was found out to be bad AND has been seen previously by Wildfire). Wildfire will also miss it if the fake exe used a stolen cert (which isnt found out to be stolen yet) to sign the executable since Wildfire currently just ignores testing such executables.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doesnt most of these bad sites belong to the "Spyware and Adware" or "Malware Sites" url category which you could just block?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried some urls from &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.spywarewarrior.com/rogue_anti-spyware.htm"&gt;http://www.spywarewarrior.com/rogue_anti-spyware.htm&lt;/A&gt;&lt;SPAN&gt; and most of them turned up belonging to the "Spyware and Adware" or "Malware Sites" url category according to www.brightcloud.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 21:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41386#M30419</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-12T21:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Rogue/Fake Antivirus Malware detection?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41387#M30420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: times new roman,times;"&gt;The Malware group was a gap for us that we are fixing this week.&amp;nbsp; We had all of the other types of nasty groups already filterd.&lt;/SPAN&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 21:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rogue-fake-antivirus-malware-detection/m-p/41387#M30420</guid>
      <dc:creator>carlboyer</dc:creator>
      <dc:date>2012-03-12T21:53:31Z</dc:date>
    </item>
  </channel>
</rss>

