How to stop Trojan:win32/Dynamer!ac from coming back

Anonymous
2016-02-02T00:30:56+00:00

Hi all,

Windows Defender found Trojan:win32/Dynamer!ac virus during a full scan - and I keep quarantining and removing it and it keeps coming back. It is in my D: drive on HP Notebook -  the Recovery Drive and I can't remove anything - is this real or a false positive? If it’s real how do I remove it?

I’m on Windows 8.1 Here’s the infected file – that I can’t access

Items:

containerfile:D:\preload\install.wim

file:D:\preload\install.wim->(Image20548)\Program Files (x86)\WildGames\House of 1000 Doors Family Secrets\HouseOf1000Doors_FamilySecrets-WT.exe->(EXEEmb)->(EXEEmb)

Spybot- Avast - TDSSKiller - Malwarebytes - and RKill couldn't find it.

Any help would be greatly appreciated.

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2016-02-29T22:38:53+00:00

Barnes99  said on February 24, 2016:

Problem solved! Yesterday, I did another update and scan with Windows Defender, and the scan did NOT find the Trojan:win32/Dynamer!ac virus. This forum and patience with MS has apparently paid off. Again, in my case, I am talking about an HP 2000 Notebook PC with Windows 10. HIP HIP Hurray! Has anybody else's luck with this changed, recently?

=====

dreamWheasler replied on February 24, 2016:

Yes! I, too, ran two scans:

  1. Windows Defender Custom - just on "D:\preload" (where Dynamer!ac had been roosting) = clean!
  2. Windows Defender Full (w/ no exclusions) = clean!

. . . also, no other threats were found.

Thank you both for your feedback.

No 'official' confirmation but it seems that starting with definition version 1.213.6922.0 (and above) made available on Feb 23, 2016 at 03:48 AM UTC, the problem has been solved indeed (updated definitions for Dynamer!ac).

At the time of this post, the latest definitions are 1.213.7574.0, dated: Feb 29, 2016 9:19 PM UTC.

You may now take off the temporary exclusion previously set for the recovery partition [1].

Hope all is well now for everyone on this thread.

=========================================================

[1] Good time to review Monkey's suggestions in this thread regarding the 'obsoleteness' of such RP.

Was this answer helpful?

0 comments No comments
Answer accepted by question author
Anonymous
2016-02-20T20:15:27+00:00

Thanks for your feedback.

FWIW... Re-posting/Re-phrasing from previous posts and/or related threads:

The suspected FP detection is of a pattern of bits within a compressed recovery partition file that matches bits for software classified as malware, but it wouldn't be active or running where located anyway.

Signatures are updated regularly to detect new malware, so it would appear there is something about the current signatures that are now detecting that bit of code in your backup image as the subject malware. That is believed to be a false positive, but since we can't be 100% sure - and MS is taking their time to revert with a fix (if any - updated definitions) - that's why I suggested earlier to run a few other scanners to confirm if it is false or not.

Whilst awaiting for someone from the Team to come by to confirm it (or not) or otherwise state how to proceed to remove subject threat, my recommendation still being to be patient and follow the advice to exclude that location from scanning rather than trying to remove the affected file you can't access anyway. You may wish to exclude only the image file rather than the entire restore partition since there is no reason to, when the problem is only one file and excluding that will suffice to stop the 'noice'.

Hope this helps.

Was this answer helpful?

0 comments No comments
Answer accepted by question author
Monkey57 3,535 Reputation points
2016-02-17T13:46:22+00:00

While it may be a false positive, I do not suggest treating it as such, until if it has been declared as such, from your antivirus mfg.  The area of concern, is non-critical, and mfg suggest you make a off-line restore media, also.  I suggest removing the restore partition, even if is not reporting suspicious files.

Please see Create a Recovery Drive-

http://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning/how-to-stop-trojanwin32dynamerac-from-coming-back/9776b54b-bdac-4517-a7c4-c5dcae240ec4?page=3

Was this answer helpful?

0 comments No comments

56 additional answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2016-02-20T21:27:50+00:00

    Yes, good. I have run other scanners and they haven't found any other problems at all. This Dynamer!ac has only been found by Defender and only in "D:\preload". And it is only the fact that Defender finds it that raises concern. I have not recognized any outstanding problems with computer function.

    I will run scans excluding D:\preload and then run one on D:\preload alone to see if it is still there. In the meantime, hopefully a solution will come to light and a proper removal of this nuisance will occur!

    Thanks

    Was this answer helpful?

    0 comments No comments