Endpoint Protection

 View Only
Expand all | Collapse all

Defwatch.dwh

Migration User

Migration UserJun 04, 2013 01:09 PM

ℬrίαη

ℬrίαηJun 04, 2013 01:17 PM

Migration User

Migration UserJun 05, 2013 01:06 AM

  • 1.  Defwatch.dwh

    Posted Jun 04, 2013 12:33 PM

    Hi every one,

     

    I have some problem with infected logs.

    some of the computers infected in this location  "c:\Documents and Settings\All Users\Application Data\Symantec\DefWatch.DWH\ dwh*.exe"

    scan type: Defwatch

    Risk: w32.sality.AE, Suspicious cloud2.

    operating system : windows XP sp3

    please clarify me is this virus.



  • 2.  RE: Defwatch.dwh

    Posted Jun 04, 2013 12:37 PM

    This is a known issue. What version of SEP are you running? Is this a managed or unmanaged client?



  • 3.  RE: Defwatch.dwh

    Posted Jun 04, 2013 01:09 PM

    Symantec Endpoint Protection 12.1.2015.2015 (RU2)



  • 4.  RE: Defwatch.dwh

    Posted Jun 04, 2013 01:11 PM

    hi every one

     

    version is: Symantec Endpoint Protection 12.1.2015.2015 (RU2)

    managed client



  • 5.  RE: Defwatch.dwh

    Posted Jun 04, 2013 01:11 PM

    You can check the same thread here:

    https://www-secure.symantec.com/connect/forums/sep-121-and-dwhtmp-files-0

    In the AV policy, on the Quarantine tab under When New Virus Definitions Arrive, set it to "Do Nothing"

    This will stop the dwh.tmp files from appearing.



  • 6.  RE: Defwatch.dwh

    Posted Jun 04, 2013 01:15 PM

    hi everyone,

     

    but in my logs   : \DefWatch.DWH\ dwh*.exe

    .exe file showing not .temp file

     

     

     

    thanks for your response



  • 7.  RE: Defwatch.dwh

    Posted Jun 04, 2013 01:17 PM

    Can you post a screenshot?



  • 8.  RE: Defwatch.dwh

    Posted Jun 05, 2013 01:06 AM
      |   view attached

    hi everyone

     

    i am attached screen shot

     

    thanks



  • 9.  RE: Defwatch.dwh

    Posted Jun 05, 2013 01:02 PM

    These look to be false positives generated by the defwatch scan. Do you have items in quarantine currently?

    You can check the quarantine in the SEP client:

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\<version name>\SRTSP\Quarantine



  • 10.  RE: Defwatch.dwh

    Posted Jun 06, 2013 02:55 AM

    hi,

     

    no items found in this Quarantine folder

     

    thanks



  • 11.  RE: Defwatch.dwh

    Broadcom Employee
    Posted Jun 06, 2013 08:22 AM

    Hi,

    According to the fix notes of latest SEP version i.e. SEP 12.1 RU2, issue is resolved with this release.

    Repeated detection of DWHxxxx.tmp as a threat
    Fix ID: 2718341
    Symptom: Repeated detection of DWHxxxx.tmp as a threat when a Defwatch scan runs on Quarantined items.
    Solution: Increased Defwatch scan performance and moved the temporary extraction folder from %TEMP% to Application Data to avoid conflicts with Windows Search Indexer.
     
    Reference: New fixes and enhancements in Symantec Endpoint Protection 12.1 Release Update 2
     
    If issue reoccuring with SEP 12.1 RU2 version then need log a case with the Support.
     

    But before that I would suggest to test it with SEP 12.1 RU3 Beta/RTM version.

    Please check this article

    DWH***.tmp files are detected in the user profile temp directory

    http://www.symantec.com/docs/TECH92399

    These detections do not indicate a new outbreak of a threat.  The .tmp files are created by the Symantec Endpoint Protection (SEP) or Symantec AntiVirus (SAV) Quarantine scan. The scan is normally initiated by a virus definition update.

    There are also several known methods to work around the issue:

    • The quarantine scan on virus definition update can be disabled in the  Symantec Endpoint Protection Manager (SEPM): edit Antivirus and Antispyware policy > Windows Settings > Quarantine > General, under "When New Virus Definitions Arrive" choose "Do nothing".
    • Items in quarantine can be deleted.
    • If the indexing service is enabled it could be triggering the issue when the dwh***.tmp files are indexed.
    • Investigate other applications that are scanning the temp file for changes.

     



  • 12.  RE: Defwatch.dwh

    Posted Jun 06, 2013 08:28 AM

    The issue seems to be with DWHxx.exe, not DWHxx.tmp. I've never seen the DWHxx.exe issue before. You may need to call support to troubleshoot further or wait for 12.1 RU3, which should be due out in the coming days.



  • 13.  RE: Defwatch.dwh

    Posted Jul 18, 2013 12:19 PM

    Is there a resolution to this or is this normal behavior? We are seeing it with Suspicious.Cloud.5 and DefWatch.DWH\dwhxxxx.exe files on a Windows 7 Enterprise machine running SEP 12.1.2015.2015 (managed).



  • 14.  RE: Defwatch.dwh

    Posted Jul 18, 2013 01:38 PM

    The workaround is to not scan the quarantine when new definitions arrive. There is not a true fix for this.