Virus/Win32.WGeneric.ajdriy - OneDriveSetup.exe

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Virus/Win32.WGeneric.ajdriy - OneDriveSetup.exe

L2 Linker

Hi,

 

Since yesterday April 13/2020 I have been getting Virus alerts in the Threat log on my PAN 3020. It has pointed out that OneDriveSetup.exe is the culprit.

 

I went to a few machines and searched for OneDriveSetup.exe and uploaded it to VirusTotal. All came back clean. I then ran a malware scan (Cortex) on a few machines and again it came back clean. I waited until today to see if the new AV signatures were adjusted, but they were not as I am still getting alerts today.

 

Has anyone else received these? From what I am seeing it is looking like a false positive.

 

Thanks

1 accepted solution

Accepted Solutions

Hello @hhiggins 

 

I am glad the signature 341427639, is been disabled. 

 

This new signature, Virus/Win32.WGeneric.ajepxx, has a very high VT detection https://www.virustotal.com/gui/file/002a33f2f0d47c03a80539b71f3a312d146fa8c671ce8627254cfa0dd55d3407...

Are you sure it is detected in OneDriveSetup.exe

 

Best 

Himani

Himani Singh

View solution in original post

21 REPLIES 21

L4 Transporter

Hello @hhiggins 

 

Thank you for bringing this to our attention. We have noticed a few other similar issues. I am glad it is been resolved. Please let me know if I can answer any more questions.

 

Best 

Himani Singh

Good morning @hisingh 

 

We are still seeing these alerts. How did you resolve the problem?

 

Thanks!

-Aaron

@hisingh ,

 

This is NOT resolved. This is STILL a problem.

L0 Member

This appears to be a false positive kicked off by the latest sync app update.

 

https://docs.microsoft.com/en-us/onedrive/sync-client-update-process

@abrickeen I would agree it is likely a false positive. We need PAN to adjust their content signatures.

 

For me, this started with the Antivirus 3316-3827 content version.

 

 

Hello @hhiggins 

 

Can you share the hash please, I will check the current status.

 

Best

Himani Singh

Hello @hhiggins@abrickeen, and @AaronBeck 

 

Thank you for waiting for my response. If you all are seeing the TID: 341427639, this signature is been disabled today, which means Wildfire signature is disabled immediately, and the AV signature will be disabled tomorrow if nothing goes wrong.  You can safely put in a threat exception for Threat ID: 341427639 to get traffic moving again.

If your threat ID is different then 341427639, share it with me.

 

Best regards,

Himani

Himani Singh

Thanks @hisingh . I will check tomorrow to see if this behavior stops. Does this mean there was an issue identified with the Antivirus content?

@hisingh I still see the EXE being flagged as a virus. Today, with the new content updates, the virus is being flagged differently. 

 


Virus/Win32.WGeneric.ajepxx

ID 341677293

 

@AaronBeck @abrickeen are you seeing this as well?

 

 

@hhiggins 

It looks like it stopped around 5:10:41 AM PST 4/15/2020.

Hello @hhiggins 

 

I am glad the signature 341427639, is been disabled. 

 

This new signature, Virus/Win32.WGeneric.ajepxx, has a very high VT detection https://www.virustotal.com/gui/file/002a33f2f0d47c03a80539b71f3a312d146fa8c671ce8627254cfa0dd55d3407...

Are you sure it is detected in OneDriveSetup.exe

 

Best 

Himani

Himani Singh

@hisingh I have had no alerts for 24 hours now. I would consider this resolved at this point.

 

Thanks

L1 Bithead

This has recently started occurring again and is filling up my SIEM. Please help @hisingh !

Hello @AaronBeck 

 

Thanks for sharing with me. 
This signature is disabled since April 2020. How are you seeing it?

https://threatvault.paloaltonetworks.com/?query=Win32.WGeneric.ajdriy&type=

 

Best

Himani

Himani Singh
  • 1 accepted solution
  • 28014 Views
  • 21 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!