<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69690#M40359</link>
    <description>&lt;P&gt;Hello Community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wonder if anyone else is getting a FalsPositive-Hit in AntiVirus-Protection on downloading Silverlight.exe?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we use the following Link: &lt;A href="http://go.microsoft.com/fwlink/?LinkID=623682" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkID=623682&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;the page is blocked do to AntiVirus-Profile. In our ThreatLog we can see that the file Silverlight.exe is beeing blocked because it is identified as Virus/Win32.slugin.ozi ID: 2044771.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running a PA-3020 in an HA-Pair with the follwing SW-Version:&lt;/P&gt;
&lt;P&gt;sw-version: 6.1.6&lt;/P&gt;
&lt;P&gt;app-version: 546-3064&lt;BR /&gt;app-release-date: 2015/12/17&amp;nbsp; 13:57:30&lt;BR /&gt;av-version: 1724-2202&lt;BR /&gt;av-release-date: 2015/12/20&amp;nbsp; 04:00:02&lt;BR /&gt;threat-version: 546-3064&lt;BR /&gt;threat-release-date: 2015/12/17&amp;nbsp; 13:57:30&lt;/P&gt;
&lt;P&gt;wildfire-version: 83278-90094&lt;BR /&gt;wildfire-release-date: 2015/12/21&amp;nbsp; 04:16:02&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I downloaded the file an run a scan on VirusTotal with the following result:&lt;/P&gt;
&lt;DIV class="row"&gt;
&lt;DIV class="span8 columns"&gt;
&lt;TABLE style="margin-bottom: 8px; margin-left: 8px;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;SHA256:&lt;/TD&gt;
&lt;TD&gt;bd7ec2cd5d5e31d39a183854c587681f49d1fc0de47ef79ab0ea6d509de64938&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Dateiname:&lt;/TD&gt;
&lt;TD&gt;Silverlight.exe&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Erkennungsrate:&lt;/TD&gt;
&lt;TD class=" text-green
                      "&gt;0 / 53
&lt;DIV class="popover-spot" style="clear: both; float: right; width: 125px;" data-content="Diese Datei hat ein Renommee von 100 auf einer Skala von -100 bis 100" data-placement="left" data-original-title="Renommee"&gt;&lt;IMG src="https://ip1.i.lithium.com/f940f8afad864e1b383027dd467debecbc1a7c39/68747470733a2f2f63686172742e676f6f676c65617069732e636f6d2f63686172743f6368733d313230783630266368743d676f6d266368636f3d6436306331412c33373966333226636864733d2d3130302c313030266368643d743a313030" border="0" /&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Analyse-Datum:&lt;/TD&gt;
&lt;TD&gt;2015-12-21 13:18:55 UTC ( vor 1 Minute )&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV id="votes-resume" class="pull-right margin-right-1"&gt;
&lt;DIV style="clear: both;"&gt;
&lt;DIV class="thumb-up pull-right" style="padding: 0px 8px;"&gt;
&lt;DIV class="pull-right button vote popover-spot" data-content="Klicken Sie hier, wenn Sie der Meinung sind, dass diese Datei harmlos ist. Bitte tun Sie dies nur, wenn Sie dafür einen triftigen Grund haben." data-original-title="Als harmlos bewerten" data-placement="bottom"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="thumb-down pull-right"&gt;
&lt;DIV id="malicious-votes" class="pull-right value text-red" style="display: block;"&gt;0&lt;/DIV&gt;
&lt;DIV class="pull-right button vote popover-spot" data-content="Klicken Sie hier, wenn Sie der Meinung sind, dass diese Datei schädlich ist. Bitte tun Sie dies nur, wenn Sie dafür einen triftigen Grund haben." data-original-title="Als schädlich bewerten" data-placement="bottom"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="goodware-message" class="alert alert-success" style="margin-bottom: 0px;"&gt;&lt;STRONG&gt;&lt;I class="icon-smile"&gt;&lt;/I&gt; Probably harmless!&lt;/STRONG&gt; There are strong indicators suggesting that this file is safe to use.&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To me it seems to be a FalsePositive.&lt;/P&gt;
&lt;P&gt;Is anyone seeing the same issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Alex.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Dec 2015 13:22:01 GMT</pubDate>
    <dc:creator>Alex_Graser</dc:creator>
    <dc:date>2015-12-21T13:22:01Z</dc:date>
    <item>
      <title>FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69690#M40359</link>
      <description>&lt;P&gt;Hello Community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wonder if anyone else is getting a FalsPositive-Hit in AntiVirus-Protection on downloading Silverlight.exe?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we use the following Link: &lt;A href="http://go.microsoft.com/fwlink/?LinkID=623682" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkID=623682&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;the page is blocked do to AntiVirus-Profile. In our ThreatLog we can see that the file Silverlight.exe is beeing blocked because it is identified as Virus/Win32.slugin.ozi ID: 2044771.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running a PA-3020 in an HA-Pair with the follwing SW-Version:&lt;/P&gt;
&lt;P&gt;sw-version: 6.1.6&lt;/P&gt;
&lt;P&gt;app-version: 546-3064&lt;BR /&gt;app-release-date: 2015/12/17&amp;nbsp; 13:57:30&lt;BR /&gt;av-version: 1724-2202&lt;BR /&gt;av-release-date: 2015/12/20&amp;nbsp; 04:00:02&lt;BR /&gt;threat-version: 546-3064&lt;BR /&gt;threat-release-date: 2015/12/17&amp;nbsp; 13:57:30&lt;/P&gt;
&lt;P&gt;wildfire-version: 83278-90094&lt;BR /&gt;wildfire-release-date: 2015/12/21&amp;nbsp; 04:16:02&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I downloaded the file an run a scan on VirusTotal with the following result:&lt;/P&gt;
&lt;DIV class="row"&gt;
&lt;DIV class="span8 columns"&gt;
&lt;TABLE style="margin-bottom: 8px; margin-left: 8px;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;SHA256:&lt;/TD&gt;
&lt;TD&gt;bd7ec2cd5d5e31d39a183854c587681f49d1fc0de47ef79ab0ea6d509de64938&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Dateiname:&lt;/TD&gt;
&lt;TD&gt;Silverlight.exe&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Erkennungsrate:&lt;/TD&gt;
&lt;TD class=" text-green
                      "&gt;0 / 53
&lt;DIV class="popover-spot" style="clear: both; float: right; width: 125px;" data-content="Diese Datei hat ein Renommee von 100 auf einer Skala von -100 bis 100" data-placement="left" data-original-title="Renommee"&gt;&lt;IMG src="https://ip1.i.lithium.com/f940f8afad864e1b383027dd467debecbc1a7c39/68747470733a2f2f63686172742e676f6f676c65617069732e636f6d2f63686172743f6368733d313230783630266368743d676f6d266368636f3d6436306331412c33373966333226636864733d2d3130302c313030266368643d743a313030" border="0" /&gt;&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Analyse-Datum:&lt;/TD&gt;
&lt;TD&gt;2015-12-21 13:18:55 UTC ( vor 1 Minute )&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV id="votes-resume" class="pull-right margin-right-1"&gt;
&lt;DIV style="clear: both;"&gt;
&lt;DIV class="thumb-up pull-right" style="padding: 0px 8px;"&gt;
&lt;DIV class="pull-right button vote popover-spot" data-content="Klicken Sie hier, wenn Sie der Meinung sind, dass diese Datei harmlos ist. Bitte tun Sie dies nur, wenn Sie dafür einen triftigen Grund haben." data-original-title="Als harmlos bewerten" data-placement="bottom"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="thumb-down pull-right"&gt;
&lt;DIV id="malicious-votes" class="pull-right value text-red" style="display: block;"&gt;0&lt;/DIV&gt;
&lt;DIV class="pull-right button vote popover-spot" data-content="Klicken Sie hier, wenn Sie der Meinung sind, dass diese Datei schädlich ist. Bitte tun Sie dies nur, wenn Sie dafür einen triftigen Grund haben." data-original-title="Als schädlich bewerten" data-placement="bottom"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="goodware-message" class="alert alert-success" style="margin-bottom: 0px;"&gt;&lt;STRONG&gt;&lt;I class="icon-smile"&gt;&lt;/I&gt; Probably harmless!&lt;/STRONG&gt; There are strong indicators suggesting that this file is safe to use.&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To me it seems to be a FalsePositive.&lt;/P&gt;
&lt;P&gt;Is anyone seeing the same issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Alex.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 13:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69690#M40359</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2015-12-21T13:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69705#M40364</link>
      <description>&lt;P&gt;We haven't...(20k+ users)&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 18:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69705#M40364</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-12-21T18:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69801#M40396</link>
      <description>&lt;P&gt;Thanks for your info, Brandon!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did another test today (using this link: &lt;A href="http://go.microsoft.com/fwlink/?LinkID=623682" target="_blank"&gt;http://go.microsoft.com/fwlink/?LinkID=623682&lt;/A&gt; ) , since were now on AV-Version 1726-2204, but again it is identified as Virus/Win32.slugin.ozi ID: 2044771&lt;/P&gt;
&lt;P&gt;In our AV-Profile we set the action for http to block. Never had any issues before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VirusTotal still states: &lt;STRONG&gt;Probably harmless!&lt;/STRONG&gt; There are strong indicators suggesting that this file is safe to use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alex.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 10:57:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69801#M40396</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2015-12-23T10:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69804#M40398</link>
      <description>&lt;P&gt;Hi Alex&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you open a support case with TAC? They could investigate and remediate the issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 12:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69804#M40398</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-12-23T12:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69864#M40417</link>
      <description>&lt;P&gt;We have the same issue.&lt;/P&gt;
&lt;P&gt;Our PA found it in traffc between our WSUS server and Windows 7 client.&lt;/P&gt;
&lt;P&gt;Apparently our other&amp;nbsp;PA did not detect if when the WSUS server downloaded it from the Internet or at that moment its was running antoher AV definition version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 19:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69864#M40417</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2015-12-24T19:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69867#M40418</link>
      <description>&lt;P&gt;I just downloaded Silverlight via the link that was posted and WildFire saw it as clean.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1744i1FCCB858B8EB8246/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="silver.JPG" title="silver.JPG" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the versions we are currently running:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1745iD44DEC276F496E5A/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="version.JPG" title="version.JPG" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sounds like a TAC case is the best option?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 20:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69867#M40418</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-12-24T20:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: FalsePositive on Silverlight.exe (Virus/Win32.slugin.ozi ID: 2044771)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69941#M40432</link>
      <description>&lt;P&gt;Thanks for all of your replies!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn´t open a case yet, because it looks like i´m not able to open one direct at PaloAlto. We have Premium Partner Support, so I think I would have to contact our Partner. Now, between Christmas and NewYear it´s a little bit tricky here!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, I tested again today, since we´re now an AV-Version 1731-2209 (12/27/15) and it looks like it is corrected now!&lt;/P&gt;
&lt;P&gt;Maybe anyone else contacted TAC &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks to all!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alex.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 08:24:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/falsepositive-on-silverlight-exe-virus-win32-slugin-ozi-id/m-p/69941#M40432</guid>
      <dc:creator>Alex_Graser</dc:creator>
      <dc:date>2015-12-28T08:24:56Z</dc:date>
    </item>
  </channel>
</rss>

