<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HEUR:Exploit.Multi.DrvDoc.gen in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122973#M4473</link>
    <description>&lt;P&gt;We have had a number of calls today for checkpoint detecting&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;"C:\ProgramData\CheckPoint\Endpoint Security\TPCommon\Updater\ATPS\Working\652743B2ED95EABB5DE5D88CDC51BF9E396216CD\cuckoo\protections\general\UID612340.pyc" as&amp;nbsp;HEUR:Exploit.Multi.DrvDoc.gen&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Currently working under the assumption of a false positive, but trying to verify with checkpoint support.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Anyone else getting this today?&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Mon, 05 Jul 2021 12:03:23 GMT</pubDate>
    <dc:creator>Ashley_Black</dc:creator>
    <dc:date>2021-07-05T12:03:23Z</dc:date>
    <item>
      <title>HEUR:Exploit.Multi.DrvDoc.gen</title>
      <link>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122973#M4473</link>
      <description>&lt;P&gt;We have had a number of calls today for checkpoint detecting&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;"C:\ProgramData\CheckPoint\Endpoint Security\TPCommon\Updater\ATPS\Working\652743B2ED95EABB5DE5D88CDC51BF9E396216CD\cuckoo\protections\general\UID612340.pyc" as&amp;nbsp;HEUR:Exploit.Multi.DrvDoc.gen&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Currently working under the assumption of a false positive, but trying to verify with checkpoint support.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Anyone else getting this today?&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:03:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122973#M4473</guid>
      <dc:creator>Ashley_Black</dc:creator>
      <dc:date>2021-07-05T12:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: HEUR:Exploit.Multi.DrvDoc.gen</title>
      <link>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122988#M4475</link>
      <description>&lt;P&gt;Looks like open a TAC case is the way to go according to&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122953" target="_blank"&gt;https://community.checkpoint.com/t5/Endpoint/Checkpoint-blocked-its-own-updater-UID612340-pyc-as-Trojan/m-p/122953&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:47:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122988#M4475</guid>
      <dc:creator>Ashley_Black</dc:creator>
      <dc:date>2021-07-05T13:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: HEUR:Exploit.Multi.DrvDoc.gen</title>
      <link>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122993#M4476</link>
      <description>&lt;P&gt;Observed this and verified with TAC as false positive. As per TAC, signature should be updated in next couple of hours.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:13:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/HEUR-Exploit-Multi-DrvDoc-gen/m-p/122993#M4476</guid>
      <dc:creator>Hamad_Altaf</dc:creator>
      <dc:date>2021-07-05T14:13:42Z</dc:date>
    </item>
  </channel>
</rss>

