False Positive on Win32/Hotbar

While reviewing systems after a three day vacation, I noticed that Microsoft Security Essentials (MSE) had identified a potential Adware:Win32/Hotbar issue on several machines (see below). Upon further research, I discovered that MSE was flagging it’s own signature update as a threat! Click here for explanation.

Adware:Win32/Hotbar
Category: Adware
Description: This program has potentially unwanted behavior.

Recommended action: Review the alert details to see why the software was detected. If you do not like how the software operates or if you do not recognize and trust the publisher, consider blocking or removing the software.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:
file:C:\Windows\Temp\05CF9286-54A9-4EBA-83E0-696343501064-Sigs\98110B50-5C07-4433-AC63-E73247E812BAmpasdlta.vdm.new.temp  <– These are Microsoft Security Essentials own virus
file:C:\Windows\Temp\05CF9286-54A9-4EBA-83E0-696343501064-Sigs\98110B50-5C07-4433-AC63-E73247E812BAmpasdlta.vdm.old.temp    <– definition files being flagged as suspect malware!

 

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.