False Positive AV block

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

False Positive AV block

L0 Member

Hi,
Not sure if this is under the correct category but here we go.
I have a false positive in my FWs, I have a file called Pv7_00_169SetupFull.exe which the FWs are detecting as Virus/Win32.WGeneric.qxdip

If I upload and scan the file with VirusTotal it gives all green lights: https://www.virustotal.com/#/file/e36d3bb4f9eaff256ecd50f4a6875e41d65d12ef87d06bf7bde79874e989e259/d...

Thanks in advance

1 accepted solution

Accepted Solutions

L7 Applicator

Sounds like a signature collision.

https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-is-a-signature-collision/ta-...

 

Sometimes benign files collide with signatures generated for False Positives, and the collision can be resolved by fixing the FP.

There are other instances where a file may be colliding with the signature of a true malware sample.


In that case the general recommendation will be to configure an Antivirus exception.

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/create-threat-exce...

 

In very particular situations, (where a signature for a true malware file causes a massive amount of collisions) we can work with PE files to make the signature more specific.

 

In any case, your issue should be worked through a Support case.

Please open a case with Support.

View solution in original post

1 REPLY 1

L7 Applicator

Sounds like a signature collision.

https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-is-a-signature-collision/ta-...

 

Sometimes benign files collide with signatures generated for False Positives, and the collision can be resolved by fixing the FP.

There are other instances where a file may be colliding with the signature of a true malware sample.


In that case the general recommendation will be to configure an Antivirus exception.

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/threat-prevention/create-threat-exce...

 

In very particular situations, (where a signature for a true malware file causes a massive amount of collisions) we can work with PE files to make the signature more specific.

 

In any case, your issue should be worked through a Support case.

Please open a case with Support.

  • 1 accepted solution
  • 4956 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!