Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SEP11: General virus/scanning behavior question

Updated: 12 Jan 2012 | 3 comments
MIXIT's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hi all.  Just wanted to ask about some odd stuff I've noticed on one of my computers.  On a Win7 machine, every couple of days or so, File System AutoProtect will pick up BloodHound.281  via Heuristic scanning.  It never does anything in response but Log-Only, even though I have Action 1 and Action 2 set to either Quarantine or Delete the risk. 

The file it identifies is new each time but always resides in c:\users\username\AppData\Local\Temp\ and is always of a randomized filename starting with D, such as the most recent example, DWH7D67.tmp .  Every time I go to manually peruse the folder, of course such file or similar files are not to be found. 

A Full Scan never finds anything and definitions are updated daily.  I've had this for other a month on this PC now, no other odd behavior observed. 

This very same behavior with these DWxxxxxx.tmp files being flagged as a virus is something I have observed at some client sites for a few years now.  In the end I usually just rebuild the machine since SEP can never deal properly with the virus. 

I tried Symnatec Power Eraser but it found nothing. 

I really doubt I am dealing with a virus so potent that no manner of scanning will defeat it, so I am wondering if anybody knows of this issue and can make suggestions.  I believe this is a common issue because I've seen this at at least 3 of my clients sites in the past 2 years and now am seeing the same thing on one of my computers.  There is no common media shared amongst myself and my clients so the virus sources are different and I doubt I am the only IT person on earth so, I figure lots of others have seen this :)

Or perhaps this is just a false positive repeating over and over.  

Thanks anybody!

Comments

greg12's picture
12
Dec
2011
1 Vote +1
Login to vote

Some links

If you don't have a brand-new SEP version, these links may help you:

DWH***.tmp files are detected in the user profile temp directory

http://www.symantec.com/docs/TECH92399

 

When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

http://www.symantec.com/docs/TECH102953

 

Here is a thread referring to the same or similar problem:

https://www-secure.symantec.com/connect/forums/cannot-remove-tmp-files-appdatalocaltemp

Mithun Sanghavi's picture
13
Dec
2011
1 Vote +1
Login to vote

Understanding.

Hello,

This is a known issue with the older versions of Symantec Endpoint Protection version 11.x

Incase, if you are carrying an older version of SEP, it would be adviced to install the Latest version of SEP 11.0.7101

OR 

Migrate to the SEP 12.1.1000

AND 

Create a policy as suggested below:

  1. Open Symantec Endpoint Protection Manager (SEPM)
  2. Select Policies
  3. Select Antivirus and Antispyware Policy
  4. Select Quarantine
  5. Click on the Cleanup Tab
  6. Under Quarantined Files check mark "Delete oldest file to limit folder Size at ( X ) MB (Instead of X mentioned the Size of Quarantine Folder normally selected.)

 

  • If you have frequent recurrences of this issue and would like to disable re-scanning of the quarantine folder please follow these steps:
  • Disable re-scanning of quarantine files.

    From the SEP-Manager:
    - Edit the Antivirus and Antispyware policy of affected clients.
    - In the policy editor click "Quarantine" on the left-hand menu.
    - On the general tab click "Do nothing" under the heading "When new Virus Definitions Arrive"

     

    Also, to remove the DWxxxxxx.tmp, follow the steps as provided in the Article below:

    https://www-secure.symantec.com/connect/articles/issue-related-low-disk-space

    Hope that helps!!

    Mithun Sanghavi
    Symantec Technical Support Engineer, SEP
    MIM | MCSA | SCTS | ITIL v3

    Follow me on Twitter: @mithun_sanghavi

    Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

    wmujawar's picture
    16
    Dec
    2011
    0 Votes 0
    Login to vote

    thank you Mithun

    thank you Mithun