ITGURU Posted December 13, 2024 Posted December 13, 2024 Have received an AV alert as below for one machine this evening, assuming false positive? NT AUTHORITY\NETWORK SERVICE ran C:\Windows\System32\svchost.exe, which attempted to access C:\Windows\Temp\{87176960-33FF-434F-AEB6-DD4FC42CA28A}-MicrosoftEdge_X64_131.0.2903.99_131.0.2903.86.exe. The Trojan named Artemis!EE8475BFFD4C was detected and deleted.
sigma Posted December 13, 2024 Posted December 13, 2024 Not necessarily. I’d still isolate the device and scan. It’s likely quicker to rebuild than investigate thoroughly.
ZeroHour Posted December 16, 2024 Posted December 16, 2024 Yeah I would rebuild to be safe as there is stuff out there that pretends to be an Edge update.
Fazza Posted December 17, 2024 Posted December 17, 2024 Artemis is malware that specifically attacks through a web browser. Why do you think it's a false positive? Its located in the temp folder which is a working area that Edge would use when downloading web pages you are viewing on the internet. A web page has been visited that contained the malware so was therefore on the PC and the endpoint protection software has deleted it for you. Personally I would clear the browsing cache for the last week and delete the whole of the TEMP folder that it references.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now