<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wininetplugin.dll showing as Virus in PAN OS 8.1.9 h4 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/287838#M76754</link>
    <description>&lt;P&gt;Hello ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forwarded your email to my colleague who did the Hash lookup and he also found nothing threat related.&lt;/P&gt;&lt;P&gt;He also said its an OS update Win 10 file from Microsoft.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the time being i allowed it but i am not sure should i keep it excluded.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; ?&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2019 12:35:24 GMT</pubDate>
    <dc:creator>khanshahidnazir</dc:creator>
    <dc:date>2019-09-11T12:35:24Z</dc:date>
    <item>
      <title>Wininetplugin.dll showing as Virus in PAN OS 8.1.9 h4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286296#M76567</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I was running a windows 7 to 10 update setup and in between i got some error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After finding out (Wininetplugin.dll) is showing as Virus and that was the error reason.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you guys please explain a bit more about this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks &amp;amp; Appreciate&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 11:31:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286296#M76567</guid>
      <dc:creator>khanshahidnazir</dc:creator>
      <dc:date>2019-09-03T11:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Wininetplugin.dll showing as Virus in PAN OS 8.1.9 h4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286351#M76574</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked at the Threat Vault from PANW, and do not see any false postive messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What was the virus signature name and ID that you saw.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you confirm that this .dll did NOT have a true positive virus attached to it?&lt;/P&gt;&lt;P&gt;Did you only rely on your endpoint AV not flagging it or quarating this file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise, so we can help you.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 18:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286351#M76574</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-09-03T18:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Wininetplugin.dll showing as Virus in PAN OS 8.1.9 h4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286471#M76597</link>
      <description>&lt;P&gt;Greetings &amp;amp; Good Day To You Too ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the ID &amp;amp; Virus Description&amp;nbsp;&lt;/P&gt;&lt;P&gt;Threat ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:&amp;nbsp; 268424925&lt;BR /&gt;Threat Name :&amp;nbsp; Virus/Win32.WGeneric.aavcql&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried in our corporate AV which is Symantec and it showed file as clean.&lt;/P&gt;&lt;P&gt;Would appreciate inputs from you.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 05:35:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286471#M76597</guid>
      <dc:creator>khanshahidnazir</dc:creator>
      <dc:date>2019-09-04T05:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wininetplugin.dll showing as Virus in PAN OS 8.1.9 h4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286835#M76656</link>
      <description>&lt;P&gt;Howdy again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I thought... how do you know that the Symantec had the most current signatures available to it.&lt;/P&gt;&lt;P&gt;The signature you provided, I went to the Threat Database and found the hash for the signature&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;44e0fa6a16669f1ed7ae4ea7bb0ac2100f67faf1ab6d38a11d47b70eba205766&lt;/P&gt;&lt;P class=""&gt;Name: Virus/Win32.WGeneric.aavcql&lt;/P&gt;&lt;P class="tabbed-header Pre-71 Post-71"&gt;Unique Threat ID: 268424925&lt;/P&gt;&lt;P class=""&gt;Create Time: 2019-05-01 20:42:43 (UTC)&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I goto Virus Total, that specific hash cannot be found.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It has been documented that Wildfire can find Malware hours/days/weeks before the other AV vendors see it.&lt;/P&gt;&lt;P&gt;Now, I am not suggesting either way a false postive or not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my (albeit layman) perspective, your AV did not find match a known AV signature&lt;/P&gt;&lt;P&gt;Are you able to confirm that your AV vendor has a signature for the hash above?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if you AV is looking for an signature that is not in its database, does that imply that a new zero day malware could not evade detection?&amp;nbsp; If that is true... then can you provide validation that the file is not, malware.&lt;/P&gt;&lt;P&gt;Absence of a response does not mean it is safe... it means there was no comparision... so still a gray area.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my thoughts.&amp;nbsp; You can open a ticket with TAC... eitherwise, we may be at an impasse.&amp;nbsp; I simply do not know....&lt;/P&gt;&lt;P&gt;What do you suggest we do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 23:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/286835#M76656</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-09-05T23:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Wininetplugin.dll showing as Virus in PAN OS 8.1.9 h4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/287838#M76754</link>
      <description>&lt;P&gt;Hello ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forwarded your email to my colleague who did the Hash lookup and he also found nothing threat related.&lt;/P&gt;&lt;P&gt;He also said its an OS update Win 10 file from Microsoft.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the time being i allowed it but i am not sure should i keep it excluded.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; ?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 12:35:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wininetplugin-dll-showing-as-virus-in-pan-os-8-1-9-h4/m-p/287838#M76754</guid>
      <dc:creator>khanshahidnazir</dc:creator>
      <dc:date>2019-09-11T12:35:24Z</dc:date>
    </item>
  </channel>
</rss>

