McAfee False Alerts on Trog Bar and Others
McAfee Security Center and Anti Virus recently started giving false alerts on one of the DLLs in Trog Bar, calling it a Trojan and quarantining it when you try to install. This file (htmlayout.dll) is clean, and it is used by numerous vendors in the industry, who are also affected. We’re working to get this issue resolved quickly. In the meantime there are a few ways you can work around this:
Option 1: Disable “Artemis”
Artemis is the heuristic portion of McAfee. Its job is to identify software that looks like it might be a problem, and zap it. This is the portion of McAfee that has incorrectly flagged htmlayout.dll. (Probably because htmlayout.dll has a lot of internet logic built in, which it uses to load css and other user interface files.)
In versions 8.x and 9.0 of Security Center you can only disable Artemis by uninstalling it from Control Panel/Add or Remove Programs (XP), Programs/Uninstall a Program (Vista), where it will be listed separately.
Starting with version 9.3, it is possible to disable Artemis:
- double-click the taskbar icon to open Security Center
- Click Advanced Menu (bottom left)
- Click Configure (left)
- Click Computer & Files (top left)
- Click Advanced (right)
- Select Active Protection (left)
- You can turn it off at the right.
Option 2: Restore the File
If you don’t want to disable Artemis, or for some reason you can’t, you can restore the file instead.
- Double-click the taskbar icon to open Security Center
- Click Advanced Menu (bottom left)
- Click Configure (left)
- Click Computer & Files (top left)
- Disable VirusScan in the right-hand module and tell it for how long.
- Then click the Restore button (left & assuming it was quarantined) & restore the item.
After restoring the file you should add an exception to prevent it from being re-scanned and re-quarantined.
Further Discussion
You can see some running dialog on this issue in the McAfee forums, here:




[...] McAfee Artemis False Alerts on Trog Bar and Others 9Sep2009 Filed under: McAfee Author: Author Hello there! If you are new here, you might want to subscribe to the RSS feed for updates on this topic.Powered by WP Greet BoxMcAfee Security Center and Anti Virus recently started giving false alerts on one of the DLLs in Trog Bar, calling it a Trojan and quarantining it when you try to install. This file (htmlayout.dll) is clean, and it is used by numerous … Follow this link: McAfee Artemis False Alerts on Trog Bar and Others [...]
Pingback by McAfee Artemis False Alerts on Trog Bar and Others | MyDailySecurity.com — 9 September 2009 @ 8:32 pm
[...] this link: McAfee Artemis False Alerts on Trog Bar and Others Share and [...]
Pingback by McAfee Artemis False Alerts on Trog Bar and Others — 10 September 2009 @ 2:44 am
RESOLVED
Today, after inquiring again, we received the following notices from McAfee:
================
Avertâ„¢ Sample Analysis
Issue Number:5505560
Virus Researcher: Brant Yaeger
Identified: No Virus/Trojan
McAfee Avertâ„¢ Labs, Beaverton, USA
Thank you for submitting your suspicious file.
Synopsis -
McAfee(R) Avert(R) Labs researchers have examined the file in question and no malware was found.
Solution -
McAfee(R) Artemis technology provides real-time protection that secures enterprises and consumers from threats as they strike and much quicker than traditional signatures can be deployed. As Artemis is updated in real-time there is no requirement to wait for a full DAT update nor to use an EXTRA.DAT intermediate solution. Simply wait approximately 30 minutes and this false will no longer exist or trigger on your system. Depending on the network settings you have or the caching involved between your system and ours it may take slightly longer for this false alarm to be resolved.
Solution -
To ensure that you have the maximum available capability of detecting and cleaning this malware on your system, please make sure you have the latest engine.
================
We apologize for any inconvenience caused by this issue.
This file is no longer detected with the Artemis product. At the time I
looked into this issue, there was no Artemis detection on the file.
As Artemis detection is real-time, there is no need for a DAT update.
Regards,
Brant Yaeger
Virus Research Analyst
McAfee(r) Avert(r) Labs
A division of McAfee, Inc.
Comment by Kevin Crenshaw — 24 September 2009 @ 3:04 pm