04-14-2020 06:07 AM
Hi,
Since yesterday April 13/2020 I have been getting Virus alerts in the Threat log on my PAN 3020. It has pointed out that OneDriveSetup.exe is the culprit.
I went to a few machines and searched for OneDriveSetup.exe and uploaded it to VirusTotal. All came back clean. I then ran a malware scan (Cortex) on a few machines and again it came back clean. I waited until today to see if the new AV signatures were adjusted, but they were not as I am still getting alerts today.
Has anyone else received these? From what I am seeing it is looking like a false positive.
Thanks
04-15-2020 08:22 AM
Hello @hhiggins
I am glad the signature 341427639, is been disabled.
This new signature, Virus/Win32.WGeneric.ajepxx, has a very high VT detection https://www.virustotal.com/gui/file/002a33f2f0d47c03a80539b71f3a312d146fa8c671ce8627254cfa0dd55d3407...
Are you sure it is detected in OneDriveSetup.exe
Best
Himani
04-14-2020 08:12 AM
Hello @hhiggins
Thank you for bringing this to our attention. We have noticed a few other similar issues. I am glad it is been resolved. Please let me know if I can answer any more questions.
Best
04-14-2020 08:27 AM
Good morning @hisingh
We are still seeing these alerts. How did you resolve the problem?
Thanks!
-Aaron
04-14-2020 08:44 AM - edited 04-14-2020 08:56 AM
04-14-2020 10:52 AM
This appears to be a false positive kicked off by the latest sync app update.
https://docs.microsoft.com/en-us/onedrive/sync-client-update-process
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!