?
Solved

Trojan Horse DWH####.tmp w/Symantec Corp 10.2.0.298

Posted on 2009-04-06
5
Medium Priority
?
9,887 Views
Last Modified: 2013-11-22
I am running Symantec Corp 10.2.0.298 with updated signatures.  I'm getting multiple notifications a day, the filename is always DWH####.tmp and always with a count of 2.  The action taken by the my AV is to quarantine.  Does anyone know what is Trojan is or know of a removal tool?  Thanks
0
Comment
Question by:markswelch
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 29

Expert Comment

by:QPR
ID: 24076012
0
 
LVL 15

Accepted Solution

by:
xmachine earned 200 total points
ID: 24076051
Hi,

1) Check the following KB article:

http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/5acc619d5a30571b882573980069a3cd?OpenDocument

2) Download & run CCleaner to clean junk temp files

http://www.ccleaner.com/download

3) Download & run "Symantec Intelligent Updater" to update and overwrite any corrupted definitions

http://definitions.symantec.com/defs/20090405-003-i32.exe

Or visit this link and choose the correct antivirus software version

http://www.symantec.com/business/security_response/definitions/download/detail.jsp?gid=savce


A Symantec Certified Specialist @ your service
0
 
LVL 2

Author Closing Comment

by:markswelch
ID: 31566961
Great response.  Thanks!
0
 

Expert Comment

by:EternalMycah
ID: 24273117
NOTE: for people trying the steps in this solution, please make sure that in CCleaner's advanced options that you UNCHECK the box "Only delete files in Windows Temp folders older than 48 hours".  Otherwise you will keep the last couple of days worth of temp files in that folder.

Sorry, but this didn't work for me.  I have been dealing with this problem showing up intermittently for over a year now on several different user's machines.  Unfortunately, it is hard to test if any "solution" (none have worked for me still) has worked or not because I have to wait until the next day until the problem pops back up.

Although I did the steps recommended in the solution yesterday, I had CCleaner's default setting to leave the last 48 hours of temp files.  So, I'll have to wait until tomorrow to see if it works by changing that setting.

However, I "THINK" the real problem is that the quarantined files are still sitting there and getting rescanned each time.  So, in addition to running CCleaner set to delete all temp files I deleted all the files listed in quarantine.  SAV > View > Quarantine.

System: Vist SP1, SAV 10.2
0
 

Expert Comment

by:EternalMycah
ID: 24306545
I got this taken care of FINALLY!!!

The key here is to delete all the files listed in quarantine.  SAV > View > Quarantine

Otherwise, everytime you get new virus definitions, you will continue having this problem.  Since by default, SAV rescans your Quarantine folder after receiving new definitions.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Curious about the latest ransomware attack? Check out our timeline of events surrounding the spread of this new virus along with tips on how to mitigate the damage.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question