Windows 10: Zerologon EventID 5827 false-positive?

Discus and support Zerologon EventID 5827 false-positive? in AntiVirus, Firewalls and System Security to solve the problem; Hi mates, I have a lot of DC patched Sep 2020 patch to monitor events related to Zerologon. My graylog showed PCs got the EventID 5827 and I updated... Discussion in 'AntiVirus, Firewalls and System Security' started by Tran Minh Tien, Dec 15, 2020.

  1. Zerologon EventID 5827 false-positive?


    Hi mates,


    I have a lot of DC patched Sep 2020 patch to monitor events related to Zerologon. My graylog showed PCs got the EventID 5827 and I updated for those PCs and enabled 3 policies:

    -Domain member: Digitally encrypt or sign secure channel data always

    -Domain member: Digitally encrypt secure channel data when possible

    -Domain member: Digitally sign secure channel data when possible

    as Microsoft's instruction. But those PCs still logged on graylog with EventID "5827 The Netlogon service denied a vulnerable Netlogon secure channel connection from a machine account." and make lots of confuse to my team if everything work fine.

    Could you please explain for me about those cases when we enabled the policies but still got the alerts?


    Thanks & Regards

    :)
     
    Tran Minh Tien, Dec 15, 2020
    #1
  2. Snixtor Win User

    False positive for desktop shortcut scanner.lnk

    The 1.239.488.0 virus / spyware definition update that rolled out about 24 hours ago appears to be producing a false positive for any shortcut placed on the desktop called "Scanner.lnk". I can consistently replicate a false positive for Trojan:Win32/FakeSysdef
    with the following steps.

    • Create a shortcut to an exe file.
    • Place the shortcut on the desktop.
    • Name the shortcut "Scanner".
    • Run "Quick Scan".
    I don't get the same result by directly scanning the file, nor by uploading the file to www.virustotal.com, so it would appear this is as a result of a heuristic rather than a file content analysis. I also don't get the same result with a shortcut that links
    to a website.

    Can anyone else replicate? How can we go about getting the Windows Defender team to reconsider this heuristic? It's a bit heavy-handed.
     
    Snixtor, Dec 15, 2020
    #2
  3. defender false positive

    Hi Bob,

    To better assist you, kindly verify the following:

    • Where did you submit the file about Windows Defender being false positive?
    • Right after the recent Windows 10 update, your Zara Radio stopped working?
    • Regarding the 404 error, what application were you using when you got that error?

    Let us know.
     
    Joanna 777, Dec 15, 2020
    #3
  4. Zerologon EventID 5827 false-positive?

    Questioning a false positive for a Windows Defender virus scan

    Anytime you suspect a possible
    false positive
    or you want a second opinion, submit it to one of the online services that analyzes suspicious files. There are also number of web resources (URL Link Scanners) which can be used to check suspicious/unfamiliar
    sites or get second opinions.

     
    quietman7 - MVP, Dec 15, 2020
    #4
Thema:

Zerologon EventID 5827 false-positive?

Loading...
  1. Zerologon EventID 5827 false-positive? - Similar Threads - Zerologon EventID 5827

  2. Is this a false positive?

    in Windows 10 Gaming
    Is this a false positive?: I ran autorun, virustotal says it had trojan virus. Only one steam.exe existed in system.I checked hashes are the same, but I am not sure about sign whether is legit or not.I lived in Thailand, so there must have time zone differenece.The extra 32 seconds compared to the...
  3. Is this a false positive?

    in Windows 10 Software and Apps
    Is this a false positive?: I ran autorun, virustotal says it had trojan virus. Only one steam.exe existed in system.I checked hashes are the same, but I am not sure about sign whether is legit or not.I lived in Thailand, so there must have time zone differenece.The extra 32 seconds compared to the...
  4. False positive??

    in AntiVirus, Firewalls and System Security
    False positive??: Hello! I downloaded a file from web and I think I got viruses or malware from it. First, Windows Defender notified me that I got malware and I deleted all the temp and patched files from my laptop and scanned it after with Microsoft Security Scan and it said I have 0 files...
  5. False positive??

    in Windows 10 Gaming
    False positive??: Hello! I downloaded a file from web and I think I got viruses or malware from it. First, Windows Defender notified me that I got malware and I deleted all the temp and patched files from my laptop and scanned it after with Microsoft Security Scan and it said I have 0 files...
  6. False positive??

    in Windows 10 Software and Apps
    False positive??: Hello! I downloaded a file from web and I think I got viruses or malware from it. First, Windows Defender notified me that I got malware and I deleted all the temp and patched files from my laptop and scanned it after with Microsoft Security Scan and it said I have 0 files...
  7. Is this a false positive

    in Windows 10 Gaming
    Is this a false positive: I'm pretty scared cause I clicked on this link for help and it flagged as malicious https://www.virustotal.com/gui/url/419ed1cdabbd93e665156658d341edf1ef001c4158864fa4ca2ad501839a3dd7?nocache=1...
  8. Is this a false positive

    in Windows 10 Software and Apps
    Is this a false positive: I'm pretty scared cause I clicked on this link for help and it flagged as malicious https://www.virustotal.com/gui/url/419ed1cdabbd93e665156658d341edf1ef001c4158864fa4ca2ad501839a3dd7?nocache=1...
  9. is this a false positive or no?

    in Windows 10 Ask Insider
    is this a false positive or no?: [ATTACH] submitted by /u/GloomyMusician24 [link] [comments] https://www.reddit.com/r/Windows10/comments/lb83rc/is_this_a_false_positive_or_no/
  10. False negative or false positive ?

    in Windows 10 Performance & Maintenance
    False negative or false positive ?: Win 10 Home 10586.164 Did a Sfc /scannow. Result : found corrupted files but unable to repair some of them. Did a dism..../restorehealth. Result : Restore operation successful. Did a sfc /scannow right after dism. Result : found corrupted files but unable to...