ATP100 - Anti-Malware - False Positive?
Hi,
the CDR feature of the ATP100 generated many e-mails regarding Malware from different Client computers. All client IP adresses are clients with McAfee/Trellix antivirus installed.
The log entry from the ATP100 is this:
Virus infected SSI:N Type:Anti-Malware Signature Virus:DeepScan.Generic.64beffbe File:McAfee_Common_x64.msi Protocol:HTTP
When I remember correctly the engine used for Anti-Malware on the ATP is McAfee.
So the McAfee engine founds a virus in a McAfee file. Interesting!
Is there a place where I can submit this false positive to Zyxel or McAfee?
Thanks.
the CDR feature of the ATP100 generated many e-mails regarding Malware from different Client computers. All client IP adresses are clients with McAfee/Trellix antivirus installed.
The log entry from the ATP100 is this:
Virus infected SSI:N Type:Anti-Malware Signature Virus:DeepScan.Generic.64beffbe File:McAfee_Common_x64.msi Protocol:HTTP
When I remember correctly the engine used for Anti-Malware on the ATP is McAfee.
So the McAfee engine founds a virus in a McAfee file. Interesting!
Is there a place where I can submit this false positive to Zyxel or McAfee?
Thanks.
0
All Replies
-
Hi @e_mano_e,
McAfee is content filter service. As for Anti-malware, it is Bitdefender.
Will this log trigger every time when update McAfee/Trellix antivirus?
Could you share the McAfee/Trellix antivirus version information ?0 -
@Zyxel_Cooldia
McAfee shows version numbers for each module installed.
McAfee Data Exchange Layer: Version 6.0.3.646
McAfee Agent: Version 5.7.6.251
McAfee DLP Endpoint: Version 11.6.500.172
McAfee Client Proxy: Version 4.4.056
McAfee Endpoint Security Plattform: Version 10.7.0.3460
McAfee Adaptiver Bedrohungsschutz: Version 10.7.0.3590
McAfee Bedrohungsschutz: Version 10.7.0.3497
This log entry seems to be created once per day.
I've just got another customer call complaining about many CDR emails from the ATP100.
Yesterday it was another customer. Also in the morning (here in Germany).
0 -
0
-
@Zyxel_Cooldia
This problem still exists!
I just installed Trellix Endpoint Security and my ATP100 log says this:
This issue needs to be addressed now.Virus infected SSI:N Type:Anti-Malware Signature Virus:Trojan.GenericKD.c42558a9 File:McAfee_Common_x64.msi Protocol:HTTP
Under "Monitor" - "Anti-Malware" a Virus name is listed but no Hash value.
Because of the missing Hash value I was not able to add this false/positive to the allow list.
I had to disable the Anti-Malware security service.
The signatures are as follows:
Thanks.0 -
Hi @e_mano_e,It's pattern match, so there is no hash value for this.You can add Trellix Endpoint Security update server's IP in IP exception list temporarily to avoid this. (CONFIGURATION > Security Service > IP Exception)Please help us to capture packets on ATP100, we would like to check if it is false positive.Steps1) Click "Anti-Malware Signature" update firstly.2) Disable "Destroy infected file" temporarily.-To avoid infected file is destroyed by firewall. please disable "Destroy infected file" temporarily to capture Trellix Endpoint Security update.3) Go to "MAINTENANCE > Diagnostics > Packets catpure", and set up filterinterface = internal interface/lanHost IP = Text PC's IP4) Click "Capture" to start.5) Open Trellix Endpoint Security and run update.6) Once it is done, click "Stop" button, and download packets file.After completing actions above, please send me followings files in PM.1) Screenshot on AV signature version2) Screenshot on "MONITOR > Security Statistics > Anti-Malware".3) Screenshot on "MONITOR > Log > View Log" for blocked Anti-malware log.
4) Packets trace file.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 149 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 263 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight