SEP11: General virus/scanning behavior question
Hi all. Just wanted to ask about some odd stuff I've noticed on one of my computers. On a Win7 machine, every couple of days or so, File System AutoProtect will pick up BloodHound.281 via Heuristic scanning. It never does anything in response but Log-Only, even though I have Action 1 and Action 2 set to either Quarantine or Delete the risk.
The file it identifies is new each time but always resides in c:\users\username\AppData\Local\Temp\ and is always of a randomized filename starting with D, such as the most recent example, DWH7D67.tmp . Every time I go to manually peruse the folder, of course such file or similar files are not to be found.
A Full Scan never finds anything and definitions are updated daily. I've had this for other a month on this PC now, no other odd behavior observed.
This very same behavior with these DWxxxxxx.tmp files being flagged as a virus is something I have observed at some client sites for a few years now. In the end I usually just rebuild the machine since SEP can never deal properly with the virus.
I tried Symnatec Power Eraser but it found nothing.
I really doubt I am dealing with a virus so potent that no manner of scanning will defeat it, so I am wondering if anybody knows of this issue and can make suggestions. I believe this is a common issue because I've seen this at at least 3 of my clients sites in the past 2 years and now am seeing the same thing on one of my computers. There is no common media shared amongst myself and my clients so the virus sources are different and I doubt I am the only IT person on earth so, I figure lots of others have seen this :)
Or perhaps this is just a false positive repeating over and over.
Thanks anybody!
Comments
Some links
If you don't have a brand-new SEP version, these links may help you:
DWH***.tmp files are detected in the user profile temp directory
http://www.symantec.com/docs/TECH92399
When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect
http://www.symantec.com/docs/TECH102953
Here is a thread referring to the same or similar problem:
https://www-secure.symantec.com/connect/forums/cannot-remove-tmp-files-appdatalocaltemp
Understanding.
Hello,
This is a known issue with the older versions of Symantec Endpoint Protection version 11.x
Incase, if you are carrying an older version of SEP, it would be adviced to install the Latest version of SEP 11.0.7101
OR
Migrate to the SEP 12.1.1000
AND
Create a policy as suggested below:
Disable re-scanning of quarantine files.
From the SEP-Manager:
- Edit the Antivirus and Antispyware policy of affected clients.
- In the policy editor click "Quarantine" on the left-hand menu.
- On the general tab click "Do nothing" under the heading "When new Virus Definitions Arrive"
Also, to remove the DWxxxxxx.tmp, follow the steps as provided in the Article below:
https://www-secure.symantec.com/connect/articles/issue-related-low-disk-space
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3
Follow me on Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo
thank you Mithun
thank you Mithun
Would you like to reply?
Login or Register to post your comment.