Endpoint Protection

 View Only
  • 1.  Symantec Detecting.tmp file from C:\Windows\Temp as Heur.AdvML.B

    Posted Jul 27, 2020 04:10 PM
    Edited by AnithaP Jul 27, 2020 04:45 PM
    ​We have files from C:\Windows\Temp being detected as malicious as part of Auto-Protect.
    path:
    C:\Windows\Temp\WAXE0F.tmp

    The action taken: Process Terminated

    How can we know which file / process triggers this? How can we ensure if this is a false-positive? Can we submit the *.tmp for analysis? Will it be found from the source location.
    Please guide.

    Any supporting inputs appreciated .Seeking urgent support.


    ------------------------------
    A Philip
    ------------------------------


  • 2.  RE: Symantec Detecting.tmp file from C:\Windows\Temp as Heur.AdvML.B

    Broadcom Employee
    Posted Jul 28, 2020 11:52 AM
    Please open a case. You can submit the tmp files being detected as False Positives as well. https://symsubmit.symantec.com/  Select the tab "Incorrectly detected by Symantec"

    ------------------------------
    John Owens
    Principal Product Support
    Symantec
    United States
    ------------------------------