SEP problems

Discussion in 'Software' started by daldrich, Dec 24, 2011.

  1. daldrich

    daldrich Private E-2

    Just finished cleaning this system. SEP keeps detecting Trojan in it's own quarantine directory. System appears to be clean now, but this makes me worry.

    Trojan.Gen.2 APQ25.tmp c:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\ Infected 12/22/11 2:46 PM

    Trojan.Gen.2 4ef326ea.tmp C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\xfer\ Infected 12/22/11 12:37 PM

    Trojan.Gen 4EF326E8.TMP C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\xfer\ Infected 12/22/11 12:37 PM

    Thanks,
    -d
     
  2. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

  3. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    I do not know what version of SEP you are running. I found this old thread while searching for what xfer means.
    http://www.symantec.com/connect/forums/tmp-files-issue-xfer-folder
    This post seemed promising
    You might want to read the thread to see if anything there is useful.
     
  4. thomas_symantec

    thomas_symantec Private E-2

    This a known issue with SEP detecting .tmp files as a trojan.


    Quarantine scan causes Auto-Protect detections in %temp% folder
    Fix ID: 1525749

    Symptom: DWHWizard.exe starts the quarantine scan and moves quarantined files in to the %temp% folder for scanning. Auto Protect will occasionally detect these infected files.
    Solution: After extracting and re-scanning each quarantine item, the TMP file is deleted unless the state is now REPAIRABLE. Repairable files are used later, either to restore to the original location or to save back to Quarantine (REPAIR_ONLY mode). These files should be clean, so Auto-Protect should not detect anything in them.


    DWHxxxx.tmp files are scanned and re-detected when new definitions arrive or during a scheduled scan
    Fix ID: 1925607
    Symptom: DWHxxxx.tmp files are scanned and re-detected when new definitions arrive or during a scheduled scan.
    Solution: After extracting a quarantined item to a temp file, the file is deleted immediately after it is processed.

    Upgrading to the latest (SEP 11 RU7 MP1) version will resolve this issue.

    See the Symantec Endpoint Protection release notes for more details.

    http://www.symantec.com/business/support/index?page=content&id=TECH103087&key=54619
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds