StoreDesktopExtension.exe As greyware

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

StoreDesktopExtension.exe As greyware

L1 Bithead

It was repported on the 13th that StoreDesktopExtension.exe was flagged as malicious by wildfire it is now being flagged as grayware and is flooding us with alerts anyone else experiencing the same?

1 accepted solution

Accepted Solutions

L7 Applicator

Hi @OliverStussi 

 

This file was initially flagged by the Local Analysis module or WildFire but has since been reclassified as Benign globally.

If the alerts persist despite the global verdict being Benign, the endpoint may have a stale verdict in its local cache. You can force the agent to re-fetch the correct verdict by clearing its local database.

1) Open an administrative command prompt on the affected endpoint.

2) Stop the agent services (requires the agent uninstall password):

   "C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect disable
   "C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop


3) Navigate to C:\ProgramData\Cyvera\LocalSystem\Persistence3\  and delete the following files:

wf_verdicts.db
wf_verdicts.db.lru
wf_retransmissions.db


4) Restart the agent services:

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime start

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect enable

 

Let me know if your query is answered, Thank you!

 

 

View solution in original post

5 REPLIES 5

L0 Member

Nos esta pasando lo mismo con StoreDesktopExtension.exe actualmente, alguna respuesta desde Palo Alto?

727d070460fa4764822b5286b1d9b8fbb5512b6e84ad645a99cb34dcede97647

L7 Applicator

Hi @OliverStussi 

 

This file was initially flagged by the Local Analysis module or WildFire but has since been reclassified as Benign globally.

If the alerts persist despite the global verdict being Benign, the endpoint may have a stale verdict in its local cache. You can force the agent to re-fetch the correct verdict by clearing its local database.

1) Open an administrative command prompt on the affected endpoint.

2) Stop the agent services (requires the agent uninstall password):

   "C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect disable
   "C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime stop


3) Navigate to C:\ProgramData\Cyvera\LocalSystem\Persistence3\  and delete the following files:

wf_verdicts.db
wf_verdicts.db.lru
wf_retransmissions.db


4) Restart the agent services:

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" runtime start

"C:\Program Files\Palo Alto Networks\Traps\cytool.exe" protect enable

 

Let me know if your query is answered, Thank you!

 

 

on our end it says the verdict changed today from benign to grayware. has it been changed back to benign since this?

OliverStussi_0-1768911966251.png

 

L1 Bithead

It is now being flagged as benign for us

Gracias por tu respuesta, 

Por el momento las alertas cesaron, y en nuestra consola tambien fue marcado como Benign.

  • 1 accepted solution
  • 248 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!