version-fox/vfox

[BUG]: Trojan Artemis!606BC678830E

Closed this issue · 3 comments

Version

0.6.5

OS

Microsoft Windows 11 Pro
10.0.26100 Build 26100

Describe the bug

McAffee antivirus detects vfox.exe as a trojan on access and deletes it.

Analyzer / Detector

Analyzer content creation date 2025.4.23. 9:02 AM
Product name McAfee Endpoint Security
Product version 10.7.0.3497
McAfee GTI query Yes
Task name On-Access Scan
Feature name On-Access Scan

Threat

Action taken Delete
Threat category Malware detected
Threat detected on creation No
Threat event ID 1027
Threat handled Yes
Threat name Artemis!606BC678830E
Threat severity Critical
Threat timestamp 2025.4.25. 12:46 PM
Threat type Trojan

Source

Source hostName -
Source process name C:\Program Files\PowerShell\7\pwsh.exe

Target

Target access time 2025.4.25. 12:46 PM
Target create time 2025.3.11. 4:29 PM
Target file size (bytes) 12503552
Target hash 606bc678830e835d9838bbcde33404db
Target host name -
Target modify time 2025.4.10. 2:19 PM
Target name vfox.exe
Target path C:\Program Files\vfox
Target user name -

Other

Cleanable Yes
Detection message McAfee Endpoint Security detected a threat.
Detection quarantine ID {9A910F85-FCCF-48B9-82D2-B8DA7E7B746B}
Duration before detection (days) 14
Description - ran C:\Program Files\PowerShell\7\pwsh.exe, which attempted to access C:\Program Files\vfox\vfox.exe. The Trojan named Artemis!606BC678830E was detected and deleted.
First action status Succeeded
First attempted action Delete pending
Second attempted action n/a

It seems there is no good solution...

I downgraded to 0.6.2 and that still works.

Sounds like something you need to tell McAfee (report false positive), not vfox... After all, they delete it, not vfox itself!