Endpoint Protection

 View Only
Expand all | Collapse all

Trojan and virus in folder the Quarantine

ℬrίαη

ℬrίαηNov 26, 2013 12:19 PM

Migration User

Migration UserNov 26, 2013 12:24 PM

  • 1.  Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 11:51 AM
      |   view attached

    Hi friends,
    i have a problem on the client that have SEPM 12.1, my quarantine folder grows each time it is impossible to stop it, and follow the recommendations given here http://www.symantec.com/business/support/index?page=content&id=TECH102953&profileURL=https%3A%2F%2Fsymaccount-profile.symantec.com%2FSSO%2Findex.jsp%3FssoID%3D1385483600551SpcKBx70cAGqGv9oacE89HWK2F78Kci7G1I8Q another recommendation, I see that this is a problem that has not yet been solved, opened a case on the mark more than 2 weeks and still no one calls me (Case # 05474632) I find that incredible.

    Your help is urgently needed.

    Thank you.

    JHM.



  • 2.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 11:52 AM

    This is the DWHxxx.tmp issue. It's a known bug in SEP. have you tried manually deleting the quarantine?

    Follow the steps here:

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

    Article:TECH102953  |  Created: 2007-01-19  |  Updated: 2013-04-22  |  Article URL http://www.symantec.com/docs/TECH102953

     



  • 3.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 11:53 AM

    Hope that articles help you.

    How to Manage Quarantined files.

     

    Article:TECH106443 | Created: 2008-01-03 | Updated: 2012-02-14 | Article URL http://www.symantec.com/docs/TECH106443
     
    How to delete Quarantined items from the Symantec Endpoint Protection Manager.
     


  • 4.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 11:57 AM

    I'm tired of deleting in safe mode and system mode and even there's a solution. * tmp grow uncontrollably.



  • 5.  RE: Trojan and virus in folder the Quarantine

    Broadcom Employee
    Posted Nov 26, 2013 11:59 AM

    disable scan when new definition arrives.



  • 6.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:00 PM

    Than disable scanning quarantine when new defs arrive.

    It's a known issue which will hopefully get a fix soon.



  • 7.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:03 PM
    What sep version are you using currently ?
     
    This issue resolved on SEP 12.1.2
     
    Repeated detection of DWHxxxx.tmp as a threat
    Fix ID: 2718341
    Symptom: Repeated detection of DWHxxxx.tmp as a threat when a Defwatch scan runs on Quarantined items.
    Solution: Increased Defwatch scan performance and moved the temporary extraction folder from %TEMP% to Application Data to avoid conflicts with Windows Search Indexer

     

     

    http://www.symantec.com/business/support/index?page=content&id=TECH199676

     



  • 8.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:08 PM

    It's not truly fixed in 12.1.2, 12.1.3, or 12.1.4. It still exists, it's only improved in future releases.



  • 9.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:16 PM

    my version is 12.1.3001

    Now I'm testing the effect disable Quarantine scan when new firms arrive.



  • 10.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:19 PM

    Doing this should resolve it



  • 11.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:24 PM
      |   view attached

    the annoying message keeps coming all the time!



  • 12.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:34 PM

    You can also supress that until your testing is complete



  • 13.  RE: Trojan and virus in folder the Quarantine

    Trusted Advisor
    Posted Nov 26, 2013 12:38 PM

    Hello,

    I agree. This issue seems to be resolved as I haven't come across any of such cases with Symantec Endpoint Protection 12.1 RU2 detecting DWH###.TMP files (expect one..in SEP 12.1.4)

    tmp file (DWH*****.tmp) detected as Trojan.Gen or Trojan.Gen.2 by Corp products

    http://www.symantec.com/business/support/index?page=content&id=TECH102953

    The Actual cause was with SEP 11 where the files were created by the Symantec Endpoint Protection or Symantec AntiVirus Quarantine scan. This scan is normally initiated by a virus definition update.

    The quarantine scan on virus definition update can be disabled: edit Antivirus and Antispyware policy > Windows Settings > Quarantine > General, under "When New Virus Definitions Arrive" choose "Do nothing".

    There are also several known methods to work around the issue:

    • The quarantine scan on virus definition update can be disabled in the  Symantec Endpoint Protection Manager (SEPM): edit Antivirus and Antispyware policy > Windows Settings > Quarantine > General, under "When New Virus Definitions Arrive" choose "Do nothing".
    • Items in quarantine can be deleted.
    • If the indexing service is enabled it could be triggering the issue when the dwh***.tmp files are indexed.
    • Investigate other applications that are scanning the temp file for changes.

    Check this Thread:

    http://www.symantec.com/connect/forums/sep-121-and-dwhtmp-files

    In case, the issue is re-occurying even after the above steps have been taken, then please create a case with Symantec Technical Support.

    Check these Steps below:

    How to create a new case in MySymantec

    http://www.symantec.com/business/support/index?page=content&id=TECH58873

    Phone numbers to contact Tech Support:-

    Regional Support Telephone Numbers:

    • United States: https://support.broadcom.com (407-357-7600 from outside the United States)
    • Australia: 1300 365510 (+61 2 8220 7111 from outside Australia)
    • United Kingdom: +44 (0) 870 606 6000

    Additional contact numbers: http://www.symantec.com/business/support/contact_t...

    Hope that helps!!


  • 14.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 12:52 PM

    as the message appears, I put the path Quarantine exceptions.
    No be fine if this action? Now I perform a full scan.

    I think there should be a more transparent solution, so I read several days ago this problem dates back to 2009, it's amazing that even Symantec resolved anything yet, may not be may not juggle do in these instances, but also knowing many rely on the product for this because it is the best on the market or it claims to be.



  • 15.  RE: Trojan and virus in folder the Quarantine

    Posted Nov 26, 2013 01:19 PM

    was this a fresh install or upgrade over previous versions? 

    The file name in the scan looks suspicious, get cleanwipe remove previous version of sep,install 12.1.4 the latest the greatest