Reply
Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Trojan.gen2 Help!

What are the notifications??

 

Quads

Contributor
Rgiang
Posts: 20
Registered: ‎07-29-2012

Re: Trojan.gen2 Help!

[ Edited ]

Norton was detecting more Trojan gen 2 files in the temp folder.

 

 

Scan type: Auto-Protect Scan
Event: Risk Found!
Security risk detected: Trojan.Gen.2
File: C:\Users\Ryan Giang\AppData\Local\Temp\DWH896C.tmp
Location: C:\Users\Ryan Giang\AppData\Local\Temp
Computer: MIC21
User: SYSTEM
Action taken: Pending Side Effects Analysis : Access denied
Date found: Friday, August 10, 2012 9:10:06 PM

 

 

 

Also, you said that there was issue with part of my windows. Any reccomendations on what I can do to get that fixed?

 

Thanks you so much.

-Ryan

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Trojan.gen2 Help!

what were the names of the files??

 

I am wondering 2 things

 

a) people that have had zeroaccess and anything else infect the system via the reported Flash Player update need to uninstall all to do with Flash Player and Plugins etc completely,  then go to the legit adobe Flash Player download a fresh latest version to install.

 

b)  Trojan.Gen can also be the tmp file detections for MS office products (word, excel etc).

 

Run a Full Scan with Malwarebytes Free after manually updating the definition database.

 

Quads

Contributor
Rgiang
Posts: 20
Registered: ‎07-29-2012

Re: Trojan.gen2 Help!

I posted one of the notifications I was getting from Norton In my previous post. They all seem to be DWH...tpm files. I removed all the Adobe flash players and tried to install a new one, but I am using google Chrome so it says Chrome already has flash installed.

 

I downloaded Malwarebytes Free, installed, and I am running a full scan now.

Also, I do not know if this is relevant or not, but I am having this problem on a laptop. I have a manuel switch for Wifi and if I turn that off, Norton will not detect anything.

 

Thanks in advance

-Ryan

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Trojan.gen2 Help!

[ Edited ]

Google search   DWH .tmp office

 

Looks like the Windows Update  service registry key is damaged  (wuaserv)

 

Quads

Contributor
Rgiang
Posts: 20
Registered: ‎07-29-2012

Re: Trojan.gen2 Help!

I ran Malwarebytes and it found a key gen to a game which it removed, but I’m pretty sure it wasn’t the problem.  It was the only thing detected.

 

I googled DWH .tmp office like you said and found a Symantec thread. I read through both pages. Some people say that the way to fix it is to upgrade to Symantec Endpoint Protection 11.0.6300 (RU6 MP3). I tried to download the file, but it asks for a product serial number which I don’t have since I got Norton from my school.

 

My school apparently does provide the installer for 11.0.6300. Will that one work?

 

Is there anything else you would recommend me trying?

 

Also, Since the Windows Update service registry key is damaged what can I do about it?

 

Sorry for all the trouble,

-Ryan

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Trojan.gen2 Help!

Symantec Corp is not my area for answering about that product

 

Please run the FSS.exe http://www.bleepingcomputer.com/download/farbar-service-scanner/

Make sure all the options are checked

Press "Scan".

It will create a log (FSS.txt) in the same directory the tool is run.

 

Quads

 

Contributor
Rgiang
Posts: 20
Registered: ‎07-29-2012

Re: Trojan.gen2 Help!

[ Edited ]

Here you are

 

-Ryan

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: Trojan.gen2 Help!

If you manually try to run Windows Update, does it work??

 

Quads

Contributor
Rgiang
Posts: 20
Registered: ‎07-29-2012

Re: Trojan.gen2 Help!

No it doesn't. It says it is checking for updates but errors and says something like cannot update