Reply
Super Trojan Terminator
Krusty13
Posts: 3,320
Registered: ‎05-31-2011

Re: ALERT: HotFixInstaller.exe MALWARE!

http://community.norton.com/t5/Norton-Internet-Security-Norton/Norton-failing-to-supply-fixes-withou...  :smileyindifferent:

Windows 7 x64 SP1     N360v20.3.1.22     NU16     SSR 2013     Secunia PSI     SpywareBlaster     NoScript     MBAM free     SAS free

huwyngr
Posts: 18,996
Topics: 906
Kudos: 2,331
Solutions: 337
Registered: ‎04-13-2008

Re: ALERT: HotFixInstaller.exe MALWARE!


Hammer_Bro wrote:

[ ... ]

 

Hugh, imposters are everywhere.  Just because someone parades around with a fancy name badge means jack crud.  However, in subsequent e-mails back and forth it is becoming more solidified in my mind, that, in fact, “HarryP” IS a genuine Symantec Employee. 

 

[ ... ]



I don't want to belabor this but your attitude is so unreal that it only shows a lack of knowledge of how these forums work.

 

People who post here have no choice in the descriptive phrase below their name or in the color of their name ...  This is assigned after checking by moderators. Harry P has been around since 2010 and he has posted over 400 times -- the liklihood of him not being a Symantec Employee is zero.

 

Personally I find your attitude on this condescending and bordering on "ad hominem".



Hugh
Regular Contributor
Hammer_Bro
Posts: 146
Registered: ‎12-21-2010

Re: ALERT: HotFixInstaller.exe MALWARE!

Hugh,

 

You mentioned that the person possessed a, “red name”.  I am assuming that you were referencing that Norton Employee’s names will be a red colour?  If the assumption is true, all I’m saying is that I don’t care about that.  For me to judge the measure of the man, I desired to have personal contact (through the private messaging system) which has occurred. 

 

Oh, about Pink Floyd- (from the post documenting the community Website’s slowness) yes, the timeliness of Floyd (especially for these times) is remarkably transcendent - - especially Mother Can I Trust The Government? 

 

Dave,

 

It is good to hear from you again.  I apologise if it seems as though I am being unreasonable such to the degree of that “sturgess” fellow, and you know I have the greatest respect for Hugh, Quads, yourself, and Send - - I just feel like (although Send is trying and I genuinely appreciate that) he is characterising my situation through the prism of Microsoft Windows Update, when I think more is at hand.  For example, usually Windows Updates (on XP Professional) would be under Add/Remove Programs, however, the questionable files on my “test” system (claiming to be from Microsoft) are not there, but residing loosely on C:\.  In any event, I have now submitted these questionable files to Symantec - - and will continue the cleanup of my “test” system in the meantime. 

 

One last note on the post created by “sturgess”- although I can empathize with him, I concur with the majority, it is unrealistic to believe that every virus definition will be accounted for, in large part, why I believe strongly in the contributions of reviewers like on Safe Web.  Moreso, imagine for a moment if Norton had to guarantee something to that extent - - they would go out of business! 

SendOfJive
Posts: 9,905
Kudos: 4,193
Solutions: 706
Registered: ‎02-07-2009

Re: ALERT: HotFixInstaller.exe MALWARE!

[ Edited ]

Hammer_Bro wrote:
For example, usually Windows Updates (on XP Professional) would be under Add/Remove Programs, however, the questionable files on my “test” system (claiming to be from Microsoft) are not there, but residing loosely on C:\. 

Hi Hammer_Bro,

 

The updates themselves will be listed in Add/Remove Programs.  The Hotiron Hotfix Installer folders are left behind in C:\, as explained here:

 

http://www.bleepingcomputer.com/forums/topic336675.html

Super Trojan Terminator
Krusty13
Posts: 3,320
Registered: ‎05-31-2011

Re: ALERT: HotFixInstaller.exe MALWARE!

While I am honoured you would mention me in the same breath as "...Hugh, Quads, and Send...",  There comes a point where you are either still searching for an answer to your issue,  or you are giving an opinion,  in which case there are other boards here in the Norton Community to discuss your issue.

 

Thanks,  Dave.

Windows 7 x64 SP1     N360v20.3.1.22     NU16     SSR 2013     Secunia PSI     SpywareBlaster     NoScript     MBAM free     SAS free

Regular Contributor
Hammer_Bro
Posts: 146
Registered: ‎12-21-2010

Re: ALERT: HotFixInstaller.exe MALWARE!

Trust me, Dave.  I have been searching for solid answers for this phenomenon, believe you me. 

 

I decided to re-examine Add/Remove Programs.  Granted, I found items pertaining to ‘Hotfix’, but, NOTHING SPECIFICALLY for so-called ‘HotIron’.  Astonishingly, I did find updates installed on 5/11/2012, the day the computer went berserk.  Frankly, I’m not certain as to how this happened - - I could swear the second I saw patterns outside the norm, I immediately held down the power button, terminating all processes.  In any event, I researched the ‘KB’ reference numbers in Microsoft’s knowledge base for the updates installed, and they stem from updates released May 8th from Microsoft.  On Microsoft’s page, I still didn’t find anything about ‘HotIron’, however, the ‘KB’ numbers and description from the suspicious folders on my system matched with what was on Microsoft’s Website. 

 

At this point, I will mark Send’s first post (on this topic) as the solution, but there are still so many unanswered questions. 

 

In all my years working with Win Updates, I have NEVER seen one that impacted the OS so adversely.  Crazy CPU consumption to the point where my cursor became extremely sluggish.  Again, the last time I experienced this was confronting the Sasser Worm.  Additionally, could a Windows Update open up a command prompt window?  Then there is the instance of two [2] wuauclt.exe’s under Task Manager.  One I can understand represents Win Update Shield in the System Tray with updates ready to be installed.  Fine.  The other briefly appears (at a high resource consumption) then disappears.  Could that be the one that temporarily checks to see if an update is available? 

 

Was this update even really necessary?  I’m tempted to say if it looks and acts like malware, it is.  I call shenanigans on Microsoft!  Shame on you, Microsoft, for releasing such a poorly written update to the place where it scared numerous users into thinking that it was malware and that their protection programs failed them!  Come to think of it, the other process that I thought started with the letter “d” running concurrently with HotFixInstaller under Task Manager may have been something like “NDP30SP2-KB2656407.msp” - - another component from the updates released May 8th.  Moving forward, will there be a conflict if I try to get this update again being that I shredded it with MBAM’s FileAssassin?

 

P.S.- Although it looks like I have irreparably offended Hugh, Send is sitting back, takes a sip of his latte and remarks, “Foolish Hammer Bro, I tried to tell you HotFixInstaller was a Windows Update.  No matter, I’ll just chalk you up to another solution in my column, ha, ha, ha.”  (then his jazz music starts playing)  To that I would say, “With the behaviour exhibited, could’ve fooled me….”  :catmad: 

huwyngr
Posts: 18,996
Topics: 906
Kudos: 2,331
Solutions: 337
Registered: ‎04-13-2008

Re: ALERT: HotFixInstaller.exe MALWARE!

<< Although it looks like I have irreparably offended Hugh, >>

 

You didn't offend me at all -- I had nothing to add to how you characterised yourself in that message to two of us.



Hugh
SendOfJive
Posts: 9,905
Kudos: 4,193
Solutions: 706
Registered: ‎02-07-2009

Re: ALERT: HotFixInstaller.exe MALWARE!


Hammer_Bro wrote:

In all my years working with Win Updates, I have NEVER seen one that impacted the OS so adversely.


I have been fortunate never to have had an issue with a Microsoft Update.  But I have read some grisly stories about the interesting predicaments that they can sometimes cause.  That's why I always create a new full disk image backup prior to every Patch Tuesday.  Painstakingly undoing the damage caused by a messed-up  update is not my idea of having a good time.

Regular Contributor
Hammer_Bro
Posts: 146
Registered: ‎12-21-2010

Re: ALERT: HotFixInstaller.exe MALWARE!

Hugh,

 

Good to hear, good to hear.  Dodged a darn near bullet there.  The absolute last thing I desire is to anger someone who has masterfully crafted over 16,000 posts. 

 

Send,

 

Interesting.

 

Last note:- To all who contributed to this thread, a sincere thank you from the bottom of my heart, you gentlemen are top-notch in my book. 

 

Best,

 

H.B.