Go to Post Don't let them fail at the end. - DonRotolo [more]
Home
Go Back   Chief Delphi > Technical > Programming > NI LabVIEW
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Reply
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 07-04-2010, 22:52
Lord_Jeremy's Avatar
Lord_Jeremy Lord_Jeremy is offline
Lord_Jeremy the Procrastinator
AKA: Jeremy Agostino
FRC #1546 (Chaos Inc.)
Team Role: Electrical
 
Join Date: Jan 2007
Rookie Year: 2007
Location: Baldwin, New York
Posts: 45
Lord_Jeremy is an unknown quantity at this point
Send a message via ICQ to Lord_Jeremy Send a message via AIM to Lord_Jeremy Send a message via MSN to Lord_Jeremy Send a message via Yahoo to Lord_Jeremy
NI Virus?

Alright. So today I noticed that the laptop I use for robotics (as well as personal stuff) was running really sluggishly. I hadn't really used it since the Hofstra regional so this was the first I noticed. Then I started getting random windows exception messages about something called ringer.exe. A quick google suggested it's a piece of malware. I then realized that I didn't have any antivirus on that machine, probably an oversight from when I last reinstalled windows. Anyway I immediately installed AVG and set it on a full scan of C. So far it's found two things,
Code:
C:\d.exe - Trojan horse Downloader.Generic9.BLZP
C:\Program Files\National Instruments\RT Images\Utilities\BIOS Updater\10.3\7063\flashUpdate.exe - Trojan horse Generic12.BRCM
Obviously, the second entry really set off alarm bells. I hadn't installed LabView until a day during Hofstra, when we needed to quickly switch to something other than Java. That was the first robotics software I had installed on that OS, in fact, as I did all my Java development in Mac OS X. Is it possible that one of the updates or maybe even the National Instruments disk was tainted? I don't know how else it would get flagged like that.

EDIT:
I just did a google for flashUpdate.exe, something I probably should have done before. NI seems to say it's a false positive, but I can swear that I wasn't having any performance issues before the regional. Also I'm not really sure where I'd get malware. I very rarely download things to that computer and all my games come from Steam...
__________________
Compiling...
Compiling...
Reply With Quote
  #2   Spotlight this post!  
Unread 08-04-2010, 00:50
TD912 TD912 is offline
Registered User
AKA: Chris Leung
FRC #1989 (Viking Robotics)
Team Role: College Student
 
Join Date: Sep 2009
Rookie Year: 2009
Location: Vernon, NJ
Posts: 156
TD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud of
Re: NI Virus?

Have you plugged in flash drives used on other computers? Some types of malware spread by infecting other files, and by placing themself onto flash drives.

The NI files might have been clean, but been infected by the malware from somewhere else. Are any other files infected? If that is the only file found to be infected, your computer may not really be infected. Simply having an infected file doesn't always mean the whole system is infected.

Does anyone else have access to the computer? Perhaps they acidentally downloaded something that was malware?

Try uploading the file to VirusTotal for identification. You may have to briefly disable AVG to be able to do this, as AVG will probably try to stop you from interacting with the file. Uploading this is perfectly safe, as long as you don't actually run it.

http://www.virustotal.com/

The site is sponsored by 20+ different antivirus utilities (from AVG to McAfee to NOD32 and even ClamAV). It scans the file with all of the engines, and displays the results to you. If AVG is the only one that detects something, it is likely just a false positive.
__________________
Zip-ties, hot glue, and duct tape.

2008 New York City Regional Champions - (41/555/1989)
2009 Brunswick Eruption 8 Finalists - (1989/56/1807)
2010 PARC XIII Champions - (25/341/1989)

Over The Bump

Last edited by TD912 : 08-04-2010 at 00:53.
Reply With Quote
  #3   Spotlight this post!  
Unread 08-04-2010, 13:28
Robototes2412's Avatar
Robototes2412 Robototes2412 is offline
1 * 4 != 14
FRC #2412 (Robototes)
Team Role: Programmer
 
Join Date: Jan 2010
Rookie Year: 2007
Location: Bellevue
Posts: 312
Robototes2412 is on a distinguished road
Re: NI Virus?

or just use linux and never worry about virii again (OSX has viruses, yes, im serious)
Reply With Quote
  #4   Spotlight this post!  
Unread 08-04-2010, 14:35
TD912 TD912 is offline
Registered User
AKA: Chris Leung
FRC #1989 (Viking Robotics)
Team Role: College Student
 
Join Date: Sep 2009
Rookie Year: 2009
Location: Vernon, NJ
Posts: 156
TD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud ofTD912 has much to be proud of
Re: NI Virus?

I don't want to turn this into an OS war, but OS X and Linux both have multiple pieces of malware targeting them, although not nearly as much as Windows does. It is much harder to be infected in OS X and Linux, as the malware generally needs root "administrator" access to do anything to the system. They are both a distant varient of UNIX, which is why many open-source Linux programs can run on OS X without too many changes.

http://en.wikipedia.org/wiki/Linux_malware

Either way, the OP's computer is running Windows, and Mac and Linux malware can't run on Windows.
__________________
Zip-ties, hot glue, and duct tape.

2008 New York City Regional Champions - (41/555/1989)
2009 Brunswick Eruption 8 Finalists - (1989/56/1807)
2010 PARC XIII Champions - (25/341/1989)

Over The Bump
Reply With Quote
  #5   Spotlight this post!  
Unread 08-04-2010, 15:18
keehun's Avatar
keehun keehun is offline
Team Captain
AKA: Keehun Nam
FRC #2502 (EP Robotics)
Team Role: Leadership
 
Join Date: May 2008
Rookie Year: 2008
Location: Eden Priaire
Posts: 474
keehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond reputekeehun has a reputation beyond repute
Send a message via AIM to keehun
Re: NI Virus?

In any case, whether it's a false-positive or really infected, you should report this to NI so they can figure out what's going on. If it's a false-positive, why it's reporting as a malware, and if it's real, how it got to be there.
__________________
For by grace you have been saved through faith, and that not of yourselves; it is the gift of God, not of works, lest anyone should boast. -- Ephesians 2:8-9
2010: Quarter Finalist (MN 10,000 Lakes)
2010: Website Award (MN 10,000 Lakes)
2009: Quarter Finalist (MN 10,000 Lakes)
2009: GM Industrial Award (MN 10,000 Lakes)
Reply With Quote
  #6   Spotlight this post!  
Unread 11-02-2012, 12:27
savage24x savage24x is offline
Registered User
AKA: Kendrick Grace
FRC #2590 (Nemesis)
Team Role: Student
 
Join Date: Jan 2012
Rookie Year: 2010
Location: Robbinsville, NJ
Posts: 3
savage24x is a jewel in the roughsavage24x is a jewel in the roughsavage24x is a jewel in the roughsavage24x is a jewel in the rough
Re: NI Virus?

I'm sorry about the bump to this (2 years, but I thought it might help somebody), but I'm in the same scenario as you. I just installed LabVIEW. My computer has been running terribly slow. Yes, the file is a false positive. 8/42 Anti-Virus programs on VirusTotal show it as a Trojan Horse. This is obvioulsy not true. So I checked Task Manager. Nothing was really popping out, other than a running AVG scan. So I checked running services and started disabling National Instruments services, and eventually disabled "National Instruments mDNS Responder service". Instantly regained my speed. Problem Solved!

Again, sorry for the bump. I'm not new to forums, but I thought this was necessary.
Reply With Quote
Reply


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Anti virus Schnabel Chit-Chat 29 09-06-2007 13:52
Cellphone Virus Raven_Writer Chit-Chat 10 30-11-2004 13:47
Warning Possible Virus! Cory Chit-Chat 7 13-02-2004 02:35
Email Virus? Eric Reed General Forum 2 06-06-2002 16:02


All times are GMT -5. The time now is 03:46.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi