• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / McAfee Artemis/GTI False Positive thrashing files

McAfee Artemis/GTI False Positive thrashing files

2013-07-31 by Jason

It is currently advised to turn off the Artemis file reputation checking service of McAfee Virus Scan Enterprise. “Due to a server issue” the service is producing false positives with pretty inconsistent results. People are reporting the U3 Autorun, Cisco Communicator, and other files are being detected as malware and being quarantined. While those files being quarantined won’t lead to the blue screen nightmare a McAfee false positive created three years ago, it doesn’t seem limited to those files either.

A user with the fitting name of PoundKeyboardNow shared the following screenshot of detections on Reddit regarding the spike in detections from the Artemis/GTI (Global Threat Intelligence) service.

dat7152

McAfee has sent out a message to clarify that the problem is not a bad definition database entry (or a dat file) but is instead caused by specific Global Threat Intelligence servers in North America. Earlier it was being recommended to update past DAT 7152 to at least DAT 7153 as a solution. The current recommendation is to disable GTI temporarily. McAfee KnowledgeBase article KB78993 goes into detail of the problem and currently proposed Workaround.

Problem
McAfee has determined that Artemis/GTI File Reputation is producing some false-positive detections in North America due to a server issue.

IMPORTANT: This is not an issue with the current McAfee DAT files.

Cause
This is an issue with specific Global Threat Intelligence servers.

Solution
McAfee is investigating this issue. This article will be updated as additional information becomes available.

Workaround 1
IMPORTANT: If you have encountered an Artemis-related detection, DO NOT restart your computer, as it may become impossible to restore some files after a restart.

McAfee recommends that customers temporarily disable Global Threat Intelligence File Reputation until this issue is confirmed as resolved.

If you use GTI Proxy in your environment, you might have a cached copy of the false detection information. Perform the following steps to purge the cache:
1. Log on to the ePolicy Orchestrator (ePO) server as an administrator.
2. Open the GTI Proxy Appliance Management interface:

  • In ePO 4.6.4 or later, select Menu, Systems, GTI Proxy Appliance Management.
  • In ePO 5.0, select Menu, then, in the Systems area, select GTI Proxy Appliance Management.

3. Under Configuration, select the GTI Proxy Appliance and select Stop, Restart, or Force-Stop.

This will purge any false positive cached file reputation requests.

Workaround 2
To restore files locally through the VirusScan Enterprise (VSE) 8.x Console:
1. Open the VSE 8.x Console.
2. Double-click Quarantine Manager Policy.
3. Click the Manager tab.
4. Right-click the required item(s) and select Restore.

Workaround 3
For instructions on how to create an ePolicy Orchestrator (ePO) task to restore quarantined items, see KB69918.

NOTE: The ePolicy Orchestrator task can only restore a single file at a time. McAfee is working on an automated solution to restore all false positive detections from this issue. This section will be updated as additional information becomes available.

That article will be updated as McAfee continues their investigation.

Filed Under: Security and Privacy, Software

Trending

  • Mozilla Gets Firefox 3.6.2 Out the Door Early
    In News, Security and Privacy, Software, System Administration
  • View an Object’s Hierarchy in Active Directory
    In System Administration, Tech Solutions
  • Microsoft Surface with Windows RT available for pre-order
    In Hardware, Gadgets, and Products

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • What is the AllJoyn Router Service on Windows 10? What is the AllJoyn Router Service on Windows 10?
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • How a DirecTV bill really works in 2015 How a DirecTV bill really works in 2015
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in