False Positive: Virus/Win32.WGeneric.qqpeo(199010010)

L0 Member

False Positive: Virus/Win32.WGeneric.qqpeo(199010010)



We are getting several false positives for the following:

Hashes: MD5 - 












L0 Member

Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010)

I'm getting a similar false positive for Microsoft Directory Services/ms-ds-smbv3 - Virus/Win32.WGeneric.adwxyf. Occurs when attempting to copy Symantec Antivirus from a share. 

L0 Member

Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010)



Turns out there was a GPO to not permit logins to multiple sessions. This GPO called on a directory and copied some files locally. It wasn't until we started looking at the AV in addition to Palo we saw there was a "login.exe" being detected and flagged. After moving the user's OU and deleting the local copy, the GPO no logger applied and the alerts ceased.


Luckily there was a "misc:" field in the Palo alert which eventually tipped us off.


Best of luck!

L4 Transporter

Re: False Positive: Virus/Win32.WGeneric.qqpeo(199010010)

In the future open a case with Palo Alto networks through your portal. THis is not the place to discuss your private network. 

As a Palo Alto customer you have Support included and we could find and fix this much faster without exposing your files to the internet. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!