08-10-2012 06:13 PM
What are the notifications??
Quads
08-10-2012 06:58 PM - edited 08-10-2012 07:12 PM
Norton was detecting more Trojan gen 2 files in the temp folder.
Scan type: Auto-Protect Scan
Event: Risk Found!
Security risk detected: Trojan.Gen.2
File: C:\Users\Ryan Giang\AppData\Local\Temp\DWH896C.tmp
Location: C:\Users\Ryan Giang\AppData\Local\Temp
Computer: MIC21
User: SYSTEM
Action taken: Pending Side Effects Analysis : Access denied
Date found: Friday, August 10, 2012 9:10:06 PM
Also, you said that there was issue with part of my windows. Any reccomendations on what I can do to get that fixed?
Thanks you so much.
-Ryan
08-10-2012 07:07 PM
what were the names of the files??
I am wondering 2 things
a) people that have had zeroaccess and anything else infect the system via the reported Flash Player update need to uninstall all to do with Flash Player and Plugins etc completely, then go to the legit adobe Flash Player download a fresh latest version to install.
b) Trojan.Gen can also be the tmp file detections for MS office products (word, excel etc).
Run a Full Scan with Malwarebytes Free after manually updating the definition database.
Quads
08-10-2012 09:12 PM
I posted one of the notifications I was getting from Norton In my previous post. They all seem to be DWH...tpm files. I removed all the Adobe flash players and tried to install a new one, but I am using google Chrome so it says Chrome already has flash installed.
I downloaded Malwarebytes Free, installed, and I am running a full scan now.
Also, I do not know if this is relevant or not, but I am having this problem on a laptop. I have a manuel switch for Wifi and if I turn that off, Norton will not detect anything.
Thanks in advance
-Ryan
08-11-2012 02:09 AM - edited 08-11-2012 02:14 AM
Google search DWH .tmp office
Looks like the Windows Update service registry key is damaged (wuaserv)
Quads
08-11-2012 08:22 PM
I ran Malwarebytes and it found a key gen to a game which it removed, but I’m pretty sure it wasn’t the problem. It was the only thing detected.
I googled DWH .tmp office like you said and found a Symantec thread. I read through both pages. Some people say that the way to fix it is to upgrade to Symantec Endpoint Protection 11.0.6300 (RU6 MP3). I tried to download the file, but it asks for a product serial number which I don’t have since I got Norton from my school.
My school apparently does provide the installer for 11.0.6300. Will that one work?
Is there anything else you would recommend me trying?
Also, Since the Windows Update service registry key is damaged what can I do about it?
Sorry for all the trouble,
-Ryan
08-11-2012 08:37 PM
Symantec Corp is not my area for answering about that product
Please run the FSS.exe http://www.bleepingcomputer.com/download/farbar-se
Make sure all the options are checked
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Quads
08-11-2012 08:42 PM - edited 08-11-2012 08:43 PM
Here you are
-Ryan
08-12-2012 06:01 PM
If you manually try to run Windows Update, does it work??
Quads
08-12-2012 08:31 PM
