Virus/Win32.WGeneric.ajdriy - OneDriveSetup.exe

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Virus/Win32.WGeneric.ajdriy - OneDriveSetup.exe

L2 Linker

Hi,

 

Since yesterday April 13/2020 I have been getting Virus alerts in the Threat log on my PAN 3020. It has pointed out that OneDriveSetup.exe is the culprit.

 

I went to a few machines and searched for OneDriveSetup.exe and uploaded it to VirusTotal. All came back clean. I then ran a malware scan (Cortex) on a few machines and again it came back clean. I waited until today to see if the new AV signatures were adjusted, but they were not as I am still getting alerts today.

 

Has anyone else received these? From what I am seeing it is looking like a false positive.

 

Thanks

21 REPLIES 21

Ah, it appears to be a different name now but is triggering on the same file.

 

oneclient.sfx.ms/Win/Prod/20.084.0426.0007/OneDriveSetup.exe

 

Virus/Win32.WGeneric.aktxlj

348874710 

https://threatvault.paloaltonetworks.com/?query=348874710

 

It actually looks like there are multiple:

@hisingh 

 

Virus/Win32.WGeneric.aktxlj

Virus/Win32.WGeneric.aktpum
 

Hi

 

I have asked the team to check Virus/Win32.WGeneric.aktxlj, I will update.

Win32.WGeneric.aktpum is disabled already. 

 

Best

Himani

Himani Singh

Win32.WGeneric.aktpum Stopped at 7:10 this morning, was this just turned off? @hisingh 

Hi

 

Virus/Win32.WGeneric.aktxlj is a malware

Win32.WGeneric.aktpum was disabled on 06-28-2020. 

 

Best

Himani

 

Himani Singh

Ah, well it looks like from 7:10 - 7:11 it was triggering on the same OneDriveSetup.exe but that has stopped as well. Thanks!

AaronBeck_0-1593613817391.png

 

Arg! @hisingh ....Same problem again @AaronBeck . Virus/Win32.WGeneric.aktpum has been setting off alarm bells.

  • 28016 Views
  • 21 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!