cancel
Showing results for 
Search instead for 
Did you mean: 
will.garner
Level 7

Artemis False Positive Artemis!Heuristic.BehavesLike.Win32.Downloader.D

Our software installer YontooClientSetup.exe was recently erroneously flagged by McAfee-GW-Edition as Heuristic.BehavesLike.Win32.Downloader.D. We'd like to find out how to get it whitelisted or otherwise eliminate this false positive. It's damaging our users' experience, our partner relationships, and our business.

0 Kudos
5 Replies
ConorD62
Level 12

Re: Artemis False Positive Artemis!Heuristic.BehavesLike.Win32.Downloader.D

You might also want to upload it to VirusTotal.


False submissions should be sent via email to virus_research@avertlabs.com (mailto:virus_research@avertlabs.com) in a password protected zip (password needs to be the word 'infected' - without the quotes) - the subject line of the email should contain the word FALSE please.

0 Kudos
will.garner
Level 7

Re: Artemis False Positive Artemis!Heuristic.BehavesLike.Win32.Downloader.D

Actually we found out about the problem from a VirusTotal report - we're not McAfee in-house.

0 Kudos
Peacekeeper
Level 20

Re: Artemis False Positive Artemis!Heuristic.BehavesLike.Win32.Downloader.D

Do what Conord62 suggested that will work

Message was edited by: Peacekeeper on 14/01/11 9:28:24 PM
0 Kudos
will.garner
Level 7

Re: Artemis False Positive Artemis!Heuristic.BehavesLike.Win32.Downloader.D

Unfortunately, our mailer (google apps / gmail) won't let me send a zipped .exe. I tried renaming it as a .zip.bak (my standard trick), but the McAfee auto-responder didn't figure it out. Any suggestions? Surely we're not the only Google user!

0 Kudos
Peacekeeper
Level 20

Re: Artemis False Positive Artemis!Heuristic.BehavesLike.Win32.Downloader.D

Try emailing it to me

peacekeepertt at gmail.com

I will forward it add an explaination of what file is and web site to get software

This my rarely looked at mail addy

0 Kudos