Jump to content

Recommended Posts

Posted

Have received an AV alert as below for one machine this evening, assuming false positive?

 

NT AUTHORITY\NETWORK SERVICE ran C:\Windows\System32\svchost.exe, which attempted to access C:\Windows\Temp\{87176960-33FF-434F-AEB6-DD4FC42CA28A}-MicrosoftEdge_X64_131.0.2903.99_131.0.2903.86.exe. The Trojan named Artemis!EE8475BFFD4C was detected and deleted.

 

 

Posted

Artemis is malware that specifically attacks through a web browser. Why do you think it's a false positive?

 

Its located in the temp folder which is a working area that Edge would use when downloading web pages you are viewing on the internet. A web page has been visited that contained the malware so was therefore on the PC and the endpoint protection software has deleted it for you.

 

Personally I would clear the browsing cache for the last week and delete the whole of the TEMP folder that it references.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...