<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic yes I've received same canned in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819351#M18561</link>
    <description>&lt;P&gt;yes I've received same canned answer.&amp;nbsp; Still getting alerts so I guess updates havent propagated out yet.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2015 21:57:47 GMT</pubDate>
    <dc:creator>masmith0324</dc:creator>
    <dc:date>2015-11-12T21:57:47Z</dc:date>
    <item>
      <title>Malware false positives after Windows update releases 10.november</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819344#M18473</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is anyone else experiensing alot of what i think is FP from microsoft updates last night?&lt;/P&gt;
&lt;P&gt;I have alot of events from Firesight this night, and all of them seem to be different windows updates&lt;/P&gt;
&lt;P&gt;Network Based Malware , and the Threath name is variants of : W32.Auto&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;One of the updates that generate events are:&amp;nbsp;https://support.microsoft.com/de-de/kb/3104507&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Im not sure how to handle this, and any inputs would be great &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have used Whitelist on this specific update, but there are so many more. Do you think Sourcefire will update rules today to fix this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;EDIT: There was an update rule from yesterday, that addressed these problems so it would not generate events. Updated and all is good &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;EDIT 2: It's not All good.. i still receives ALOT of events regarding windows updates related to &amp;nbsp;Win32.Auto rule&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 08:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819344#M18473</guid>
      <dc:creator>Steelyboy77</dc:creator>
      <dc:date>2015-11-11T08:15:00Z</dc:date>
    </item>
    <item>
      <title>We are also seeing many of</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819345#M18504</link>
      <description>&lt;P&gt;We are also seeing many of these this starting last night and continuing this morning. &amp;nbsp;They all originate from Windows updates, Flash updates, or Chrome updates. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://www.virustotal.com/en-gb/file/54c0d1de00c650689c52080b8b4757f35c078f8d86da13c90601a6f6fd070aae/analysis/&lt;/P&gt;
&lt;P&gt;detected as:&amp;nbsp;W32.Auto.0372C6.182366.in02&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://www.virustotal.com/en-gb/file/36c291265b8ad791f0c004bd7e13addb217b96dce8cdd5bfcc9e4b3d88af82ab/analysis/&lt;/P&gt;
&lt;P&gt;detected as:&amp;nbsp;W32.File.MalParent&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://www.virustotal.com/en-gb/file/021b8b9bcac980aa32433919dfdc7d6eb96d5b45976786f5cdf8c22099590c2a/analysis/&lt;/P&gt;
&lt;P&gt;detected as:&amp;nbsp;W32.Auto.22510C.182440.in02&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://www.virustotal.com/en-gb/file/62a3898ef96a01fc1b2accb9bb36c56262e7896bb801534eb6d7e45d562930be/analysis/&lt;/P&gt;
&lt;P&gt;detected as:&amp;nbsp;W32.DFC.MalParent&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://www.virustotal.com/en-gb/file/9512b8b43db434c5eb6c461c8febc41ce6718e93f286637b5948a86dd773d886/analysis/&lt;/P&gt;
&lt;P&gt;detected as:&amp;nbsp;W32.Auto.740FDA.182447.in02&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All appear to be false positives from everything we can tell.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 16:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819345#M18504</guid>
      <dc:creator>Corey Melhus</dc:creator>
      <dc:date>2015-11-11T16:11:23Z</dc:date>
    </item>
    <item>
      <title>Was anyone able to open a</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819346#M18517</link>
      <description>&lt;P&gt;Was anyone able to open a Cisco case opened to detect this? Few of which we are seeing are below. These are still continuing throughout this morning.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;W32.Auto.357267.182447.in01&lt;BR /&gt;W32.Auto.83c528.182440.in01&lt;BR /&gt;W32.Auto.61CF22.182446.in02&lt;BR /&gt;W32.Auto.9ca11c.182445.in01&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 16:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819346#M18517</guid>
      <dc:creator>kaustubhmhatre</dc:creator>
      <dc:date>2015-11-11T16:54:05Z</dc:date>
    </item>
    <item>
      <title>I dont think they are false</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819347#M18532</link>
      <description>&lt;P&gt;I dont think they are false positive they have weird names&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 17:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819347#M18532</guid>
      <dc:creator>stephan</dc:creator>
      <dc:date>2015-11-11T17:26:39Z</dc:date>
    </item>
    <item>
      <title>Some of them now start to</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819348#M18542</link>
      <description>&lt;P&gt;Some of them now start to come back as Clean. Network based retrospective notifications.&lt;/P&gt;
&lt;P&gt;Like this one, with verified signature: &amp;nbsp;https://www.virustotal.com/nb/file/bebfbec521bea1c745533758908fc122fd1edca6ba54277fcce2d219832babdf/analysis/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 19:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819348#M18542</guid>
      <dc:creator>Steelyboy77</dc:creator>
      <dc:date>2015-11-11T19:22:56Z</dc:date>
    </item>
    <item>
      <title>I've received same.  Opened</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819349#M18550</link>
      <description>&lt;P&gt;I've received same.&amp;nbsp; Opened case about 12 hours ago.&amp;nbsp; They said Talos was investigating and then i started seeing them come back as clean.&amp;nbsp; But then again this afternoon the alerts kicked up again.&amp;nbsp; I believe you can reproduce by having a system go out to microsoft and check for updates.&amp;nbsp; it's definitely related to the patches that were release by microsoft yesterday&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 01:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819349#M18550</guid>
      <dc:creator>masmith0324</dc:creator>
      <dc:date>2015-11-12T01:46:11Z</dc:date>
    </item>
    <item>
      <title>This thread has some more</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819350#M18557</link>
      <description>&lt;P&gt;This thread has some more info including acknowledgement that these are false positives from TAC:&amp;nbsp;https://supportforums.cisco.com/discussion/12702996/amp-blocking-windows-updates&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 21:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819350#M18557</guid>
      <dc:creator>Corey Melhus</dc:creator>
      <dc:date>2015-11-12T21:32:15Z</dc:date>
    </item>
    <item>
      <title>yes I've received same canned</title>
      <link>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819351#M18561</link>
      <description>&lt;P&gt;yes I've received same canned answer.&amp;nbsp; Still getting alerts so I guess updates havent propagated out yet.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 21:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-false-positives-after-windows-update-releases-10/m-p/2819351#M18561</guid>
      <dc:creator>masmith0324</dc:creator>
      <dc:date>2015-11-12T21:57:47Z</dc:date>
    </item>
  </channel>
</rss>

