How to stop Trojan:win32/Dynamer!ac from coming back

Anonymous
2016-02-02T00:30:56+00:00

Hi all,

Windows Defender found Trojan:win32/Dynamer!ac virus during a full scan - and I keep quarantining and removing it and it keeps coming back. It is in my D: drive on HP Notebook -  the Recovery Drive and I can't remove anything - is this real or a false positive? If it’s real how do I remove it?

I’m on Windows 8.1 Here’s the infected file – that I can’t access

Items:

containerfile:D:\preload\install.wim

file:D:\preload\install.wim->(Image20548)\Program Files (x86)\WildGames\House of 1000 Doors Family Secrets\HouseOf1000Doors_FamilySecrets-WT.exe->(EXEEmb)->(EXEEmb)

Spybot- Avast - TDSSKiller - Malwarebytes - and RKill couldn't find it.

Any help would be greatly appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2016-02-29T22:38:53+00:00

Barnes99  said on February 24, 2016:

Problem solved! Yesterday, I did another update and scan with Windows Defender, and the scan did NOT find the Trojan:win32/Dynamer!ac virus. This forum and patience with MS has apparently paid off. Again, in my case, I am talking about an HP 2000 Notebook PC with Windows 10. HIP HIP Hurray! Has anybody else's luck with this changed, recently?

=====

dreamWheasler replied on February 24, 2016:

Yes! I, too, ran two scans:

  1. Windows Defender Custom - just on "D:\preload" (where Dynamer!ac had been roosting) = clean!
  2. Windows Defender Full (w/ no exclusions) = clean!

. . . also, no other threats were found.

Thank you both for your feedback.

No 'official' confirmation but it seems that starting with definition version 1.213.6922.0 (and above) made available on Feb 23, 2016 at 03:48 AM UTC, the problem has been solved indeed (updated definitions for Dynamer!ac).

At the time of this post, the latest definitions are 1.213.7574.0, dated: Feb 29, 2016 9:19 PM UTC.

You may now take off the temporary exclusion previously set for the recovery partition [1].

Hope all is well now for everyone on this thread.

=========================================================

[1] Good time to review Monkey's suggestions in this thread regarding the 'obsoleteness' of such RP.

Was this answer helpful?

0 comments No comments
Answer accepted by question author
Anonymous
2016-02-20T20:15:27+00:00

Thanks for your feedback.

FWIW... Re-posting/Re-phrasing from previous posts and/or related threads:

The suspected FP detection is of a pattern of bits within a compressed recovery partition file that matches bits for software classified as malware, but it wouldn't be active or running where located anyway.

Signatures are updated regularly to detect new malware, so it would appear there is something about the current signatures that are now detecting that bit of code in your backup image as the subject malware. That is believed to be a false positive, but since we can't be 100% sure - and MS is taking their time to revert with a fix (if any - updated definitions) - that's why I suggested earlier to run a few other scanners to confirm if it is false or not.

Whilst awaiting for someone from the Team to come by to confirm it (or not) or otherwise state how to proceed to remove subject threat, my recommendation still being to be patient and follow the advice to exclude that location from scanning rather than trying to remove the affected file you can't access anyway. You may wish to exclude only the image file rather than the entire restore partition since there is no reason to, when the problem is only one file and excluding that will suffice to stop the 'noice'.

Hope this helps.

Was this answer helpful?

0 comments No comments
Answer accepted by question author
Monkey57 3,535 Reputation points
2016-02-17T13:46:22+00:00

While it may be a false positive, I do not suggest treating it as such, until if it has been declared as such, from your antivirus mfg.  The area of concern, is non-critical, and mfg suggest you make a off-line restore media, also.  I suggest removing the restore partition, even if is not reporting suspicious files.

Please see Create a Recovery Drive-

http://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning/how-to-stop-trojanwin32dynamerac-from-coming-back/9776b54b-bdac-4517-a7c4-c5dcae240ec4?page=3

Was this answer helpful?

0 comments No comments

56 additional answers

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2016-02-11T03:53:31+00:00

    Reposting...

    FWIW:

    False positives are not common with Microsoft detections, which tend to be more conservative, but they happen. The recovery image is typically safe from attack, though I imagine that it is not completely safe.

    As commented earlier, the exclusion of determined location/folder/file from WD scanning shall only be deemed as a 'temp-workaround' and not a final solution.

    Anyway, I'd think it's time to escalate the problem to MS in order to get some attention from the concerned Team. I'll alert CMs/FMs about this to take action in due course. Please be patient. Someone shall revert to you soonest possible. Thanks.

    @Everyone on this thread:

    As previously commented, we have already seen this on HP machines in the recent past.

    This time, all evidence suggests a new instance of a false positive detection on same subject container (D:\preload\install.wim) for a Windows image file on the HP recovery drive.

    That game comes preloaded (you didn't install it yourself) on HP machines (as part of all their bloatware stuff) so it's legitimately part of that Windows image. It is a legitimate game, and from searching online you'll find no evidence that there is any malware that masquerades as such.

    Even if it was a real detection, please note that it is in a compressed image on a restore partition that is not easily accessed/modified; meaning, it wouldn't be an active infection.

    In any event, only MS can confirm it as a false positive, and to that end, this thread has been escalated to the concerned Team. We just need MS to confirm it as a false positive and fix the definitions.

    Please just be patient and follow the advice to exclude that location from scanning rather than trying to remove the affected file. You may also wish to exclude only the image file rather than the entire restore partition since there's no reason to when the problem is only one file and excluding that will suffice.

    While we can't give a 100% guarantee it is a FP, it almost certainly is, or the problem would occur on the system drive whenever people use the recovery process and the game is installed, and that doesn't seem to be the case.

    The problem should be resolved soon (hopefully). You have a workaround to allow the scans to work, so you need to do nothing more but wait for the power that be to fix the problem.

    Was this answer helpful?

    0 comments No comments