Endpoint Protection

 View Only
Expand all | Collapse all

DWHxxxx.tmp Trojan Horse Can't resolve

  • 1.  DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 17, 2011 10:48 AM

    I have been working on this for a week, I have searched and tried every solution on this and other sites, and I cant get rid if the message

    this just goes on and on and on creating hundreds of entries

    Here is the version 11.0.6005.562

    I am at my wits end here, Can anyone help ? is there any real solution?

    I am sure it's not a real threat and I have read it's a problem with SEP 11 but I have applied every patch and fix

    without any resolution,



  • 2.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 17, 2011 11:27 AM

    Did you read or try the following articles? They may help you:

    DWH***.tmp files are detected in the user profile temp directory

    http://www.symantec.com/docs/TECH92399

     

    When new virus definitions are in place and the quarantine is being scanned, a DWH file is created and detected by Auto-Protect

    http://www.symantec.com/docs/TECH102953

     

    Best solution may be an upgrade to 11.0.7101 where this known issue is resolved.



  • 3.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 17, 2011 11:51 AM

    Non of those links help me, I am using a Government version "for home use" and I do not have a contract number or serial number so I am unable to download an updated version.

    Any options to download an update that will not mess with my Licensing.



  • 4.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 17, 2011 12:20 PM

    Did you try to deactivate the quarantine scan on virus definition update?

    Antivirus and Antispyware policy > Quarantine > General > "When New Virus Definitions Arrive" > "Do nothing"



  • 5.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 17, 2011 08:34 PM

    Greg,

    I do not have that option,

     

     



  • 6.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 18, 2011 02:19 PM

    My proposal was for the SEP Manager console ... I assume you don't have access on it.

    Here is a post by Mithun Sanghavi with a comprehensive explanation how to get rid of the DWH* files problem:

    https://www-secure.symantec.com/connect/forums/why-it-so-difficult-get-rid-ofwork-qsp-files#comment-5255331

    Have a look at this tool which arguably makes fixing a bit more convenient (no warranty though):

    https://www-secure.symantec.com/connect/downloads/squash-symtmps-mikes-tool-set



  • 7.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Dec 19, 2011 12:41 AM

     Login to console and go to go clients tab and select the antivirus and spyware change the settings  action s should be

    1 clean and delete

    2 clean and delete

    3 delete and qurantine

    for all actions settings should be like this

    save the changes and refresh the console once and try.



  • 8.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Trusted Advisor
    Posted Dec 19, 2011 04:14 AM

    Hello,

    Appreciate Greg "Thumbs Up" to your suggestion Above.

    This is a known issue with the older versions of Symantec Endpoint Protection version 11.x

    Incase, if you are carrying an older version of SEP, it would be adviced to install the Latest version of SEP 11.0.7101

    OR 

    Migrate to the SEP 12.1.1000

    AND 

    Create a policy as suggested below:

    1. Open Symantec Endpoint Protection Manager (SEPM)
    2. Select Policies
    3. Select Antivirus and Antispyware Policy
    4. Select Quarantine
    5. Click on the Cleanup Tab
    6. Under Quarantined Files check mark "Delete oldest file to limit folder Size at ( X ) MB (Instead of X mentioned the Size of Quarantine Folder normally selected.)

  • If you have frequent recurrences of this issue and would like to disable re-scanning of the quarantine folder please follow these steps:
  •  

    Disable re-scanning of quarantine files.

    From the SEP-Manager:
    - Edit the Antivirus and Antispyware policy of affected clients.
    - In the policy editor click "Quarantine" on the left-hand menu.
    - On the general tab click "Do nothing" under the heading "When new Virus Definitions Arrive"

     

    Also, to remove the DWxxxxxx.tmp, follow the steps as provided in the Article below:

    https://www-secure.symantec.com/connect/articles/issue-related-low-disk-space

     

    Hope that helps!!



  • 9.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Apr 27, 2012 06:25 AM

    Release notes for Endpoint Protection and Network Access Control 11
    Article: TECH103087   |  Created: 2007-01-12   |  Updated: 2012-04-26   | 
    Article URL http://www.symantec.com/docs/TECH103087

    Migrating to Symantec Endpoint Protection 11.0.7200 (RU7 MP2)
    Article: TECH187333   |  Created: 2012-04-25   |  Updated: 2012-04-25   | 
    Article URL http://www.symantec.com/docs/TECH187333

    This includes an improvement to the DWH issue:

    Files re-detected during Defwatch scan
    Fix ID: 2067778
    Symptom: DWHxxxx.tmp files are being re-detected when Defwatch scan is running.
    Solution: Fixed some scan issues, making the scan faster. Also created a separate folder to rescan Quarantine items that can be used to create exceptions.

    Hope this helps!  Please do update this thread with your findings.

     



  • 10.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Trusted Advisor
    Posted Apr 27, 2012 08:12 AM

    Is RU7 MP2 really going to fix this issue?

    As there's been fixes for this issue in every release since RU5 with it not yet being resolved.

    The only way many people have been able to control this issue is to continually keep deleting the quarantined items so a new definition file will not scan and duplicate the DWHxxx.tmp files.

    From speaking with Symantec directly issue is caused by file being modified slightly while new definition download re-scans anything in quarantine folder. This slightly modified file is then re-quarantined as a separate DWHxxx.tmp file causing duplication.



  • 11.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Apr 27, 2012 10:57 AM

    Is RU7 MP2 really going to fix this issue?

    Your problem statement, that Symantec has taken several runs at this issue already, has been noted by engineering as well.  Achitecturally, this is a difficult issue to address in a CRT release because of API changes required in our core components.  The best fix would be to rescan the threat in memory rather than temporarily writing to disk.  The temporary file will always be vulnerable to redetection by auto protect depending on the system configuration and other software running.

    RU7 MP2 contains 2 improvements:

    1) "Fixed some scan issues, making the scan faster".  Engineering estimated the scan performance improvements reduce the chances of AP redetection by 90%.  Since this is not a 100% solution, engineering added the second aspect for customers still suffering with this issue.

    2) "Created a separate folder to rescan Quarantine items that can be used to create exceptions."  This option provides another 100% effective solution to the problem by allowing a scan exception to be created on the SEPM.  The new folder is used only for the temp rescan files.

    The other two workarounds already mentioned in the thread should also be 100% effective:

    1) Turn off the quarantine rescan feature, which provides limited value for most threats in the wild today.

    2) Avoid use of "quarantine" action.

    The architectural improvement to enable an in memory scan is tracked in our formal requirements management system and under discussion by product management for prioritization into a core team release.

     



  • 12.  RE: DWHxxxx.tmp Trojan Horse Can't resolve

    Posted Apr 28, 2012 11:38 PM

    As greg12 mentions, changing the Quarantine settings can only be done from the SEPM console by an SEP Administrator.

    As SEP is installed on your home computer, is this an unmanaged installation? Ask your SEP admins to do another export of the package with the Quarantine section of the AV & spyware policy set to 'do nothing' when new virus definitions arrive as per the image below.

    Alternatively, ask your SEP admins to specify a custom quarantine folder and add that custom folder to the central exclusion list. They must then export the installation package inlcuding the policies again. You must then re-install for the new policies to apply.