<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic trojan/Win32.deceiver.d - False Positive? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/trojan-win32-deceiver-d-false-positive/m-p/1264304#M7125</link>
    <description>&lt;P&gt;I have noticed that PA NGFW sees this threat&amp;nbsp;trojan/Win32.deceiver.d using Logon.exe from PCs in a specific zone (zone 1) going to our DCs that happen to be in a different zone (zone 2).&amp;nbsp; I have had a couple of users say they have to type in their credentials a couple of times but we blamed DUO for that.&amp;nbsp; In the Threat log I see only a few of the PCs in zone 1 application: ms-ds-smbv3, Type: virus or wildfire-virus, using port 445.&amp;nbsp; When I look in the Wildfire Submissions:&amp;nbsp; File name: logon.exe action: block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have Malwarebytes and Cortex - when I scan those machines - they come back clean.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone else having this issue?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2026 19:33:42 GMT</pubDate>
    <dc:creator>Tgarner3800</dc:creator>
    <dc:date>2026-09-14T19:33:42Z</dc:date>
    <item>
      <title>trojan/Win32.deceiver.d - False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/trojan-win32-deceiver-d-false-positive/m-p/1264304#M7125</link>
      <description>&lt;P&gt;I have noticed that PA NGFW sees this threat&amp;nbsp;trojan/Win32.deceiver.d using Logon.exe from PCs in a specific zone (zone 1) going to our DCs that happen to be in a different zone (zone 2).&amp;nbsp; I have had a couple of users say they have to type in their credentials a couple of times but we blamed DUO for that.&amp;nbsp; In the Threat log I see only a few of the PCs in zone 1 application: ms-ds-smbv3, Type: virus or wildfire-virus, using port 445.&amp;nbsp; When I look in the Wildfire Submissions:&amp;nbsp; File name: logon.exe action: block.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have Malwarebytes and Cortex - when I scan those machines - they come back clean.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone else having this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2026 19:33:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/trojan-win32-deceiver-d-false-positive/m-p/1264304#M7125</guid>
      <dc:creator>Tgarner3800</dc:creator>
      <dc:date>2026-09-14T19:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: trojan/Win32.deceiver.d - False Positive?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/trojan-win32-deceiver-d-false-positive/m-p/1264685#M7128</link>
      <description>&lt;P&gt;Maybe the logon.exe is dynamic and each time is different and Wildfire need to scan it. You can create rule that matches the app, the url and attach wildfire profile with not a "Hold" mode and also check the logs that it is not the Inline ML Wildfire that uses prebuild AI models for scanning without checking the Wildfire cloud.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See:&amp;nbsp; "The system applies the fall back&lt;STRONG class="ph b"&gt; policy rule&lt;/STRONG&gt; configured by the administrator, which determines whether to &lt;STRONG class="ph b"&gt;enable (permissive)&lt;/STRONG&gt; or &lt;STRONG class="ph b"&gt;block (protective)&lt;/STRONG&gt; the file."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-browser/integrations/first-party-integrations/file-handling-and-analysis-in-advanced-wildfire" target="_blank"&gt;File Handling and Analysis in Advanced WildFire&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/wildfire-features/hold-mode-for-wildfire-realtime-signature-lookup" target="_blank"&gt;Hold Mode for WildFire Real-Time Signature Lookup&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/advanced-wildfire/administration/advanced-wildfire-overview/advanced-wildfire-concepts/advanced-wildfire-inline-ml" target="_blank"&gt;Advanced WildFire Inline ML&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2026 06:11:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/trojan-win32-deceiver-d-false-positive/m-p/1264685#M7128</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-09-18T06:11:20Z</dc:date>
    </item>
  </channel>
</rss>

