cancel
Showing results for 
Search instead for 
Did you mean: 
alex1155
Level 7

Artemis!BF5B73A4CB31 false positive

This is probably a mistake

0 Kudos
6 Replies
Hayton
Level 18

Re: Artemis!BF5B73A4CB31 false positive

I picked this one at random to reply to. You've posted 19 of these, and none of them gives any information other than the Artemis detection name. What programs or applications are you running that trigger these detections?

Out of curiosity I looked into this one and I find that this one comes from the download of an EBook :

http://minotauranalysis.com/search.aspx?q=bf5b73a4cb312556f3d7741ef090cbd4

That and the VirusTotal analysis shows the download to be risky, with the possibility that you would also acquire keylogging software from the download.

So I would say that in this case it may not be a false positive. I haven't investigated the other 18 that you posted about.

If you want to have these files checked you need to submit them for analysis. See

https://community.mcafee.com/docs/DOC-1265 and

http://www.mcafee.com/us/mcafee-labs/resources/how-to-submit-sample.aspx

0 Kudos
alex1155
Level 7

Re: Artemis!BF5B73A4CB31 false positive

Hayton,

one of the files is programm "Fakturka" (polish), the second "metin2.bin" in Metin 2 game (polish).

thesse file are clean.

if you know the rest of the files you want to invite to private messages

0 Kudos
Hayton
Level 18

Re: Artemis!BF5B73A4CB31 false positive

I made the assumption that the reports I found were for the same download that you were trying to get. If I was wrong, then I apologise. The Artemis detection will be for the same reason, though : a potential risk, probably from a keylogging program. Artemis detections are difficult to assess because they rely on heuristic analysis. That's why you need to submit all of those files for checking (see the links I gave above).

0 Kudos
alex1155
Level 7

Re: Artemis!BF5B73A4CB31 false positive

Ok, I sent the files to the laboratory.
But I want to report that the removal of FP by mail or Getsusp is long, and here on the forum help is fast

0 Kudos
Peacekeeper
Level 20

Re: Artemis!BF5B73A4CB31 false positive

When you get the auto reply back reply to the email saying False Positive and detection name.

Post the analysis Id here (add them also for the others) and post back in 3 days or so if not answer back . We can then stir a tech ito look up the detection but we must give them a chance to reply.

0 Kudos
showvik
Level 12

Re: Artemis!BF5B73A4CB31 false positive

Hi,

Artemis!BF5B73A4CB31 has been suppressed.

Regards,

Showvik

0 Kudos