We are fighting an issue with Forti Client 7.2.5
We got a Malware/Virus detection on following files (multiple clients):
Malware: FSA/RISK_HIGH found in C:\Windows\WinSxS\wow64_microsoft-windows-recover_31bf3856ad364e35_10.0.19041.1_none_465905a4885947e8\recover.exe by realtime scan. The file was quarantined.
Malware: FSA/RISK_HIGH C:\Windows\WinSxS\amd64_microsoft-windows-wmpnss-ux_31bf3856ad364e35_10.0.19041.1_none_6db5d09458d426f5\wmpnscfg.exe by realtime scan. The file was quarantined C:\Windows\SysWOW64\recover.exe by realtime scan. The file was quarantined.
Malware: FSA/RISK_HIGH found in C:\Program Files\Windows Media Player\wmpnscfg.exe by realtime scan. The file was quarantined.
After running
SFC /scannow
DISM /online /Cleanup-image /ScanHealth
DISM /Online /Cleanup-Image /Checkhealth
DISM /Online /Cleanup-Image /RestoreHealth
the problem disappeared on one client, but is persistent on another one.
I have opened a ticket (TAC) and the issue is investigated. Support is expecting false positives here.
Do you also have such issues? Would be great if you report here:
Using Windows 10 and 11 with the latest patches applied.
Thanks!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
seems like to be a false positive, wondering why no one else seems to have the problem?
To say it in the words of a popular vulcan... "Fascinating..."
I think there is also the fact that other vendor firewalls apply nextgen firewall features to the local in traffic, whereas fortigates don't unless you configure a custom local in policy with virtual patch enabled. These vulnerabilities on other firewalls can be remediated through the regular security feeds and don't require you to install a patch (usually).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.