cancel
Showing results for 
Search instead for 
Did you mean: 
EricH
Level 7

Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

Hi there, I ran a full scan a few hours ago which returned a potentially unwanted program identified as Artemis!EC40C6BFF1E6. The file name C:\msworks\pss\WKS8RM9X.EXE

I previously experienced a similar alert from McAfee which turned out to be a false positive.

Has anyone else had this alert or can advise please before I remove an essential element of MSWORKS?

Best Regards

EricArtemis image.bmp

0 Kudos
1 Solution

Accepted Solutions
nchattop
Level 12

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

Hi

We analysed the file and found that this detection was triggered on Kill.exe being in the package. McAfee(R) Artemis technology provides real-time protection that secures enterprises and consumers from threats as they strike and much quicker than traditional signatures can be deployed. In future please submit your samples in password-protected zipped file (password=infected) to virus_researchers@avertlabs.com


Regards

Neha Chattopadhyay

McAfee SME

0 Kudos
22 Replies
jtweb
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

I too am getting the potential false alert. And it seems to be happening with DAT Version: 6121.0000

Screenshot - 9_30_2010 , 4_34_53 AM.gif

0 Kudos
sgreeves
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

McAfee identified the same file on my PC today.

Artemis.jpg

0 Kudos
EricH
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

As 3 people are now reporting the same possible false positive, would Vinod or someone else from McAfee like to advise us please?

Is this the right way to draw it to McAfee's attention?

0 Kudos
lennellie
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

I also got this same message this morning after my nightly scheduled scan.  I didn't have time to check into it this morning, so quarrantined it.  Now I have a message from McAfee informing me about blocking this potentially unwanted program that wants to run.  Has anyone received an answer to this warning and what we are to do?

0 Kudos
sgreeves
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

I haven't received anything from McAfee yet, although I did exclude the file from further scans.  Would you mind posting the text of the response?

Scott

0 Kudos
EricH
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

There is no response from McAfee on this item at this time. I expect them to publish their response in this open forum where it is available for all to see.

This is only the 2nd time that I have used the McAfee forum so I can only judge by the way that they responded last time. I guess that we need to give them a little time to investigate. I would also expect that the priority will rise as more people report the same issue.

If anyone with more forum experience can correct my perception I'd be grateful. Meanwhile I wait in hope for some kind of official response.

Eric

0 Kudos
nchattop
Level 12

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

Hi Erich,

We are looking into this issue and with high priority this case has been escalated to our Senior Virus Engineers, once the file is evaluated  we will email you with further updates.

In future please submit your file to virus_research@avertlabs.com in password-protected zipped file (password='infected') also if any of the file you suspect to be False, please type false, Artemis False in the subject line

Thanks & Regards

Neha Chattopadhyay

0 Kudos
sgreeves
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

Folks, I'm sorry if I'm showing my ignorance, but Eric, up above your first post is a header

Malware Discussion  >  Artemis Discussion

I clicked on Artemis Discussion and began to read some of the articles and older posts.  Is Artemis just an instant detection program by McAfee?  We seem to have had the same identifier but did it identify the same file in each of our computers?  Eric, it tagged the same file in your computer as it did mine but a different file for "jtweb".  What about you lennellie?

Scott

0 Kudos
LoriC
Level 7

Re: Artemis!EC40C6BFF1E6 - False Positive?

Jump to solution

I had the same messae today after updating McAfee and running a scan. I hope we can get an answer to this.

0 Kudos