How to stop Trojan:win32/Dynamer!ac from coming back

Anonymous
2016-02-02T00:30:56+00:00

Hi all,

Windows Defender found Trojan:win32/Dynamer!ac virus during a full scan - and I keep quarantining and removing it and it keeps coming back. It is in my D: drive on HP Notebook -  the Recovery Drive and I can't remove anything - is this real or a false positive? If it’s real how do I remove it?

I’m on Windows 8.1 Here’s the infected file – that I can’t access

Items:

containerfile:D:\preload\install.wim

file:D:\preload\install.wim->(Image20548)\Program Files (x86)\WildGames\House of 1000 Doors Family Secrets\HouseOf1000Doors_FamilySecrets-WT.exe->(EXEEmb)->(EXEEmb)

Spybot- Avast - TDSSKiller - Malwarebytes - and RKill couldn't find it.

Any help would be greatly appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2016-02-29T22:38:53+00:00

Barnes99  said on February 24, 2016:

Problem solved! Yesterday, I did another update and scan with Windows Defender, and the scan did NOT find the Trojan:win32/Dynamer!ac virus. This forum and patience with MS has apparently paid off. Again, in my case, I am talking about an HP 2000 Notebook PC with Windows 10. HIP HIP Hurray! Has anybody else's luck with this changed, recently?

=====

dreamWheasler replied on February 24, 2016:

Yes! I, too, ran two scans:

  1. Windows Defender Custom - just on "D:\preload" (where Dynamer!ac had been roosting) = clean!
  2. Windows Defender Full (w/ no exclusions) = clean!

. . . also, no other threats were found.

Thank you both for your feedback.

No 'official' confirmation but it seems that starting with definition version 1.213.6922.0 (and above) made available on Feb 23, 2016 at 03:48 AM UTC, the problem has been solved indeed (updated definitions for Dynamer!ac).

At the time of this post, the latest definitions are 1.213.7574.0, dated: Feb 29, 2016 9:19 PM UTC.

You may now take off the temporary exclusion previously set for the recovery partition [1].

Hope all is well now for everyone on this thread.

=========================================================

[1] Good time to review Monkey's suggestions in this thread regarding the 'obsoleteness' of such RP.

Was this answer helpful?

0 comments No comments
Answer accepted by question author
Anonymous
2016-02-20T20:15:27+00:00

Thanks for your feedback.

FWIW... Re-posting/Re-phrasing from previous posts and/or related threads:

The suspected FP detection is of a pattern of bits within a compressed recovery partition file that matches bits for software classified as malware, but it wouldn't be active or running where located anyway.

Signatures are updated regularly to detect new malware, so it would appear there is something about the current signatures that are now detecting that bit of code in your backup image as the subject malware. That is believed to be a false positive, but since we can't be 100% sure - and MS is taking their time to revert with a fix (if any - updated definitions) - that's why I suggested earlier to run a few other scanners to confirm if it is false or not.

Whilst awaiting for someone from the Team to come by to confirm it (or not) or otherwise state how to proceed to remove subject threat, my recommendation still being to be patient and follow the advice to exclude that location from scanning rather than trying to remove the affected file you can't access anyway. You may wish to exclude only the image file rather than the entire restore partition since there is no reason to, when the problem is only one file and excluding that will suffice to stop the 'noice'.

Hope this helps.

Was this answer helpful?

0 comments No comments
Answer accepted by question author
Monkey57 3,535 Reputation points
2016-02-17T13:46:22+00:00

While it may be a false positive, I do not suggest treating it as such, until if it has been declared as such, from your antivirus mfg.  The area of concern, is non-critical, and mfg suggest you make a off-line restore media, also.  I suggest removing the restore partition, even if is not reporting suspicious files.

Please see Create a Recovery Drive-

http://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning/how-to-stop-trojanwin32dynamerac-from-coming-back/9776b54b-bdac-4517-a7c4-c5dcae240ec4?page=3

Was this answer helpful?

0 comments No comments

56 additional answers

Sort by: Most helpful
  1. Anonymous
    2016-02-17T15:08:03+00:00

    Title: Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB3124263) - Failed to install

    This is what I found in my computer after a failed install.  I look back on my install history and all updates have failed since  January 12, 2016.  My app don't work correctly, at times I can't connect to the internet.  Why didn't defender find it till now.  Now that we are force to use Windows 10.  I would like to deleted my prior operating system in the partition D: drive because this Trojan is sill there and causing such pain in my *****.  I don't know what personal information has been compromise at this point  but I am not will to take a chance.

    Was this answer helpful?

    0 comments No comments
  2. Monkey57 3,535 Reputation points
    2016-02-17T13:50:36+00:00

    While it may be a false positive, I do not suggest treating it as such, until if it has been declared as such, from you antivirus mfg.  The area of concern, is non-critical, and mfg suggest you make a off-line restore media, also.  I suggest removing the restore partition, even if it is not reporting suspicious files.

    Was this answer helpful?

    0 comments No comments