Endpoint Protection

 View Only
Expand all | Collapse all

Autoprotect finding js.alescurf -- just keeps running

  • 1.  Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 01, 2012 01:38 PM

    I use Endpoint Protection on a Windows 7 machine. Autoprotect continues to find and quarantine js.alescurf (in appdata/local/temp), but as soon as it finds one, there are three created. I've used a command window to monitor the subdirectory, and the files just keep popping up.  So autoprotect simply continues to run, quarantining the files; it never stops.  The quarantine folder is huge.

    I've run multiple full system scans, and Symantec finds nothing.  I've run MS Malicous Tool Remover, nothing.  I've run MalwareBytes, nothing.  I've run Power Eraser... nothing.

    Can anyone give me some hints on the best way to deal with this? 



  • 2.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 01, 2012 04:29 PM

    Its either coming from some webpage or some remote machine.

    Make sure you have SEP NTP with IPS enabled and Risk Tracer enabled it will lead you to the source machine.



  • 3.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 01, 2012 07:17 PM

    Hi RHR,

    Which version of SEP are you running?  What is that file being detected as, and is it always that same filename?

    Do you have IPS and firewall, or just AV alone?

    Have you tried running a full system scan in safe mode?  Autoprotect alone is not always enough.

    Also: I recommend configuring your client to delete rather than quarantine, if quarantine size is becoming an issue.

    Hope this helps!

    Mick



  • 4.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 01, 2012 07:37 PM

    JS.Alescurf write up says that

    "JS.Alescurf is a detection for malicious code that can be injected in to vulnerable Internet Web pages."

    http://www.symantec.com/security_response/writeup.jsp?docid=2012-011213-0902-99

    So best to

    - Clear your browsers cache
    - Memorize all the website you visit and note it when the detection take place.
    - Check if your DNS server affected by the DNSchanger malware http://www.dns-ok.gov.au/

     



  • 5.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 02, 2012 09:31 AM

    Thanks. I'll give that a try.



  • 6.  RE: Autoprotect finding js.alescurf -- just keeps running

    Broadcom Employee
    Posted Apr 02, 2012 09:32 AM

    also check if there is task scheduled around that time?



  • 7.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 02, 2012 09:37 AM

    I use both chrome and firefox.  I've cleared the caches via the browsers, plus I've used CCleaner to clear them as well. The problem seems to pop up after 9pm, even if I have no browsers open; so it doesn't appear to be associated with any web site.  I'll check my DNS server.  Thanks.

     

    ETA: MY DNS server is clean.



  • 8.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 02, 2012 09:43 AM

    Good idea.  Just checked, nothing.



  • 9.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 02, 2012 09:44 AM

    I'm running SEP 11.0.6005.562.  The file name is always something like DWH9C28.tmp in ...\AppData\Local\Temp.   SEP quarantines DWH9C28.tmp and then another file with a similar name pops up immediately.

    Network threat protection is enable and configured, and I do use firewalls (one s/w and one h/w).  I ran both SEP and MalwareBytes in safe mode.



  • 10.  RE: Autoprotect finding js.alescurf -- just keeps running
    Best Answer

    Posted Apr 02, 2012 10:07 AM

    Hi RHR,

    > DWH9C28.tmp

    If all the file names are like that, then this is not a current infection / outbreak.

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect
    Article: TECH102953   |  Created: 2007-01-19   |  Updated: 2012-02-28   | 
    Article URL http://www.symantec.com/docs/TECH102953

    DWH***.tmp files are detected in the user profile temp directory.
    Article: TECH92399   |  Created: 2009-01-16   |  Updated: 2012-02-28   | 
    Article URL http://www.symantec.com/docs/TECH92399 
     
     



  • 11.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 02, 2012 02:07 PM

    Yes, this is it!  This makes sense; each time it would run, it took about twice as long, Now the quarantine file is so large, autoprotect eats up all my CPU time.

     

    Thank you!

     

     



  • 12.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 03, 2012 04:53 AM

    Later builds improved the way SEP reacts to the situations which cause the DWH detections.  I recommend upgrading now to the SEP 11 RU7 release, and then in a few weeks when RU7 MP2 is available, apply that.  After that there should be either no or very few DWH events.

    Cheers once again for using the forum, RHR! &: )



  • 13.  RE: Autoprotect finding js.alescurf -- just keeps running

    Posted Apr 03, 2012 09:22 AM

    I upgraded to 12.1.1000.157 RU1. After doing so, I was able to delete the files in the quarantine folder (( was unable to do so with my previous version) and the problem has resolved.