Virus/win32.wgeneric.ajgdai id 341892366

Reply
Highlighted
L2 Linker

Virus/win32.wgeneric.ajgdai id 341892366

Hi Team,

 

I have issue. One user connect to SSL VPN, and cannot ping one IP  192.168.1.11. Only one IP. after i checking at firewall, I found this users got blocking activity Threat Name virus/win32.wgeneric.ajgdai   id 341892366. But when this users using mobile hotspot. him can ping this IP address 192.168.1.11.

 

Palo Alto PA-220

 

Thanks

 

 


Accepted Solutions
Highlighted
Cyber Elite

Hello,

I would say investigate that node to see what is causing the alert in the AV logs. Sounds like it may be compromised?

 

Regards,

View solution in original post


All Replies
Highlighted
Cyber Elite

Hello,

Where is the IP he is trying to ping, on his network or on yours behind the VPN?

 

Please advise,

Highlighted
L2 Linker

 

HIi @OtakarKlier 

 

Thanks for reply.

 

He at home try to ping IP at the their office(Window server 2016) . At the office have Palo Alto firewall. I checked at firewall log, and found have threat from IP address this users.

 

I not sure, this threat have connection from his problem or not.

Because him problem is, cannot ping (window server 2016) when use VPN from him modem wifi, but if he using mobile hotspot and use same VPN account , he can ping all server at the office (window server 2016).

 

So what a question is, I found threat from log firewall from account VPN same (Personal cannot ping window server 2016), Is there a problem with the threat from log firewall ?

 

Thanks

 

#log threat
-Virus/Win32.WGeneric.ajgdai  341892366
-application ms-ds-smbv3
- port 445

 

Highlighted
Cyber Elite

Hello,

Is ping allowed? Is the users IP on the block list for a threat, if that is setup?

 

Regards,

Highlighted
L2 Linker

Hello,

 

Yes it allowed to ping or access or remote. Other staff can.. just him cannot ping..

 

Is the users IP on the block list for a threat, if that is setup?  NO.

 

Just him cannot ping when using wifi at home.

 

My question is, this problem related for threat log from firewall.? below screen shot log firewall.

abdulhakam_1-1588320444912.png

 

 

Highlighted
Cyber Elite

Hello,

I would say investigate that node to see what is causing the alert in the AV logs. Sounds like it may be compromised?

 

Regards,

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!