LabVIEW

cancel
Showing results for 
Search instead for 
Did you mean: 

LV 8.5, RT Virus CRYP_XED-2 Virus Alert

Came in this morning to work and found the following files "infected" with a virus.  Unfortunately, I don't know if they are necessary to run RT and LV.  Any thoughts? 
 
Here are the files: 
~\RT Images\Base\1.2\7002\ph_exec.exe
~\RT Images\Base\1.2\701d\ph_exec.exe
~\RT Images\Base\1.2\701d\safemode.exe
~\RT Images\Base\1.2\7063\ph_exec.exe
~\RT Images\Base\1.2\7151\ph_exec.exe
~\RT Images\Base\1.2\E002\ph_exec.exe
 
Are these files necessary for my system?  Can I get these files from NI's website if I delete them? 
 
Thanks,

Bill


Message Edited by upchuckjunk on 04-14-2008 04:38 PM
0 Kudos
Message 1 of 12
(5,681 Views)

Hello

I have experinced same problem with NI DAQ 861 file LVRT711_01.msi with Trend Micro OfficeScan.

 



Message Edited by thuttu77 on 04-15-2008 04:44 AM
0 Kudos
Message 2 of 12
(5,617 Views)
Hello everyone,

Thank you for your posts. National Instruments R&D is aware of this issue and we believe Trend Micro's Anti-virus software is incorrectly reporting ph_exec.exe as the 'Netsky' virus. We are in contact with Trend Micro to resolve this issue.

In summary, we believe this is a false positive on Trend Micro's part. The 'Netsky' virus does not infect certain files, it only propagates between computers. We believe Trend Micro is incorrectly reporting ph_exec.exe as a virus because 'Netsky' has a built-in SMTP engine that sends out e-mails with "spoofed" copies of itself. ph_exec.exe will not run on a host machine, but it does have its own SMTP engine within its binaries (based off early SMTP engines). It is likely the virus program sees related components required for 'Netsky' in ph_exec.exe, since the SMTP engines are probably related -- but the similarities stop there, unless there's a text string in ph_exec.exe that is used in 'Netsky' or a derivative.

Please create a service request at ni.com/support if you are experiencing this problem so we can keep you up to date on the status of our investigation. If you do not have NI Support, please reference this Discussion Forum post and include my name in the request and we will provide you temporary support for the duration of our investigation.

Thank you.

P.S. -- I am not aware of this false positive manifesting itself through our DAQ Driver. I will make DAQ R&D aware of this as well.


Message Edited by Riconquistiamola on 04-15-2008 09:57 AM

| Michael K | Project Manager | LabVIEW R&D | National Instruments |

Message 3 of 12
(5,567 Views)
We are receiving word Trend Micro released another update on Tuesday, April 15th that resolved many customer issues relating to this virus alert. Please contact NI as described in my above post if you are still experiencing issues after receiving this update.

Cheers.

| Michael K | Project Manager | LabVIEW R&D | National Instruments |

0 Kudos
Message 4 of 12
(5,445 Views)
Just as an FYI....... Avast antivirus also reports ph_exec.exe as a trojan........
0 Kudos
Message 5 of 12
(5,189 Views)

Hi thelmores,

 

Thanks for the FYI! We have observed this behavior in Avast, and a corrective action request (CAR) has been filed (#124685) to fix the problem. You can use this ID to check on the status of the request in the future. Thanks again for bringing this to our attention.

Asa Kirby
CompactRIO Product Marketing Manager
________________
Sail Fast!
0 Kudos
Message 6 of 12
(5,156 Views)

hallo all.

i use lv 8.5.

 

FYI : avira antivir also, after today's daily update, found this virus. 

 

attached is a jpg.

 

bye 

0 Kudos
Message 7 of 12
(4,976 Views)

Hi,

 

Thanks for reporting this issue with Avira. I've created a CAR for it with the ID 130684. You can use this to keep track of the issue.

 

You may also want to contact Avira and let them know that their software is incorrectly identifying this Virus.

 

Thanks!

Asa Kirby
CompactRIO Product Marketing Manager
________________
Sail Fast!
0 Kudos
Message 8 of 12
(4,949 Views)

Hi,

I've attached a virus alert about ph_exe.exe file in LV 8.6 from PrevX AV & malware software. I noticed this thread discussing a similar issue. Wanted to know if I could safely ignore it.

 

Thanks,

 

Rajeev Dubey

Rajeev Dubey

Quantum Age Tech Solutions Pvt. Ltd.

India

http://www.qagetech.com

rajeev@qagetech.com
0 Kudos
Message 9 of 12
(4,338 Views)

Hi,

I've received a virus infection alert from Prevx AV software. This relates to ph_exe.exe file. A screenshot is attached.

Could I safely ignore this? Since the thread was very similar I'm reporting this problem here though I noticed it on my computer with LV8.6

 

Rajeev Dubey

 

  

 

 

 

ph_exec_VirusAlert.gif

Rajeev Dubey

Quantum Age Tech Solutions Pvt. Ltd.

India

http://www.qagetech.com

rajeev@qagetech.com
0 Kudos
Message 10 of 12
(4,337 Views)