<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firefox Download being classified as Trojan-Downloader/Win32.banload.aumr. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50967#M37507</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Firefox 3.6.9 downloads from any of the mirros is being classified as Trojan-Downloader/Win32.banload.aumr, threat ID 2549505. Problem on Mozilla's end?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the data from the PCAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;fox/releases/3.6.9/win32/en-US/&lt;BR /&gt;&lt;BR /&gt;-Type: application/octet-stream&lt;BR /&gt;&lt;BR /&gt;MZ......................@...............................................!..L.!This program cannot be run in DOS mode.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;$........H...)u..)u..)u...~..)u.75{..)u......)u...q..)u..)t. )u.w&amp;amp;(..)u...~..)u.s/s..)u.Rich.)u.........PE..L...fJ.D.....................p...p........... ....@.................................O.......................................\...p.... ..\l...........5..............................................................................................UPX0.....p..............................UPX1................................@....rsrc....p... ...n..................@..............................................................................................................................................................................................................................................................................................................................................................................................................2.03.UPX!&lt;BR /&gt;..&lt;BR /&gt;.....e2.............&amp;amp;.......V...N.....13..Fx.Nt.H.........@.......AA..Fh.....^......41V3..F`.".FT.Xo..-\.P.,&amp;amp;.$.j....mSZN.P.J.Bj....o&lt;BR /&gt;$^..k.. ..|/..A.,0.4.p8.P(m..-L.@.DH.&amp;lt;....T.."${.&lt;BR /&gt;....xS..VW.....M.....E.lS.E.3.P.}..w.......@..u.#..E..'.G..w..ut}..F0;....E.}.j....fk....Yt..`..\....3.....m..u.t...VV.].+.....,.E........&lt;BR /&gt;.O...d.a..M.I.M.....L.E....e.V..y...&lt;BR /&gt;.S.P.Q..w..M.=..7V+w....e..P....X.m..1.;.........E.E.?....;;..Vh..1..........as.i..&lt;BR /&gt;P....;.W......Pt&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Sep 2010 15:09:01 GMT</pubDate>
    <dc:creator>mharding</dc:creator>
    <dc:date>2010-09-15T15:09:01Z</dc:date>
    <item>
      <title>Firefox Download being classified as Trojan-Downloader/Win32.banload.aumr.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50967#M37507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Firefox 3.6.9 downloads from any of the mirros is being classified as Trojan-Downloader/Win32.banload.aumr, threat ID 2549505. Problem on Mozilla's end?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the data from the PCAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;fox/releases/3.6.9/win32/en-US/&lt;BR /&gt;&lt;BR /&gt;-Type: application/octet-stream&lt;BR /&gt;&lt;BR /&gt;MZ......................@...............................................!..L.!This program cannot be run in DOS mode.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;$........H...)u..)u..)u...~..)u.75{..)u......)u...q..)u..)t. )u.w&amp;amp;(..)u...~..)u.s/s..)u.Rich.)u.........PE..L...fJ.D.....................p...p........... ....@.................................O.......................................\...p.... ..\l...........5..............................................................................................UPX0.....p..............................UPX1................................@....rsrc....p... ...n..................@..............................................................................................................................................................................................................................................................................................................................................................................................................2.03.UPX!&lt;BR /&gt;..&lt;BR /&gt;.....e2.............&amp;amp;.......V...N.....13..Fx.Nt.H.........@.......AA..Fh.....^......41V3..F`.".FT.Xo..-\.P.,&amp;amp;.$.j....mSZN.P.J.Bj....o&lt;BR /&gt;$^..k.. ..|/..A.,0.4.p8.P(m..-L.@.DH.&amp;lt;....T.."${.&lt;BR /&gt;....xS..VW.....M.....E.lS.E.3.P.}..w.......@..u.#..E..'.G..w..ut}..F0;....E.}.j....fk....Yt..`..\....3.....m..u.t...VV.].+.....,.E........&lt;BR /&gt;.O...d.a..M.I.M.....L.E....e.V..y...&lt;BR /&gt;.S.P.Q..w..M.=..7V+w....e..P....X.m..1.;.........E.E.?....;;..Vh..1..........as.i..&lt;BR /&gt;P....;.W......Pt&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 15:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50967#M37507</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-09-15T15:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firefox Download being classified as Trojan-Downloader/Win32.banload.aumr.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50968#M37508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;thanks for the heads up. This is actually good information. Can you send in an email to &lt;A href="mailto:support@paloaltonetworks.com"&gt;support@paloaltonetworks.com&lt;/A&gt; with this same information. This can then be forwarded to our content team and we can fix this in about 1 week.&lt;/P&gt;&lt;P&gt;Can you include the following in your email:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serial number of your device&lt;/P&gt;&lt;P&gt;software version&lt;/P&gt;&lt;P&gt;content version&lt;/P&gt;&lt;P&gt;virus version if applicable&lt;/P&gt;&lt;P&gt;the pcap&lt;/P&gt;&lt;P&gt;the threat id&lt;/P&gt;&lt;P&gt;the name of the threat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 22:21:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50968#M37508</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-09-15T22:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firefox Download being classified as Trojan-Downloader/Win32.banload.aumr.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50969#M37509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just sent it. Thank you very much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 13:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firefox-download-being-classified-as-trojan-downloader-win32/m-p/50969#M37509</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2010-09-16T13:20:57Z</dc:date>
    </item>
  </channel>
</rss>

