01-08-2014 05:37 AM
Since 2013/12/26 I have been seeing a large number of Suspicious DNS Queries (generic: xml12es.farolatino.com), threatid 4011926. After researching the computers that are getting this, they all seem to be going to Microsoft sites prior to this query. From what I have read this seams to be coming from Microsoft Media Player. They use this site for their online media catalog. Has anyone else seen this?
01-08-2014 07:32 AM
Hello Randy Greenspon,
This is a false positive. The signature is now disabled and the fix will be available in AV-1186.
Hope that helps!
Thanks and regards,
Kunal Adak
01-08-2014 07:32 AM
Hello Randy Greenspon,
This is a false positive. The signature is now disabled and the fix will be available in AV-1186.
Hope that helps!
Thanks and regards,
Kunal Adak
01-10-2014 07:59 AM
Thanks for confirming this and I have seen it get removed in AV-1186. However with the addition of AV-1187 we are now getting another, I believe false positive of ThreatID 4034267, generic:msreg.gale.com
01-16-2014 09:37 AM
Hello rgreens,
msreg.gale.com domain is not a false positive. "Wildfire has detected a malware sample (ba491bb1eb3d62c5520883c8a24ac08f) which tried to resolve this domain "msreg.gale.com", which can not be resolved. So a malware sample tried to visit an un-resolvable domain and hence we marked this domain as malware"
Hope that helps!
Thanks and regards,
Kunal Adak
01-20-2014 02:31 AM
Hello rgreens
I also have this problem, DNS queries:
How to fix it?
Thank you,
Diego
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!