RetouchPRO

Go Back   RetouchPRO > Tools > Software
Register Blogs FAQ Site Nav Search Today's Posts Mark Forums Read


Software Photoshop, Lightroom, Paintshop Pro, Painter, etc., and all their various plugins. Of course, you can also discuss all other programs, as well.

Anyone know if this is a false positive?

Reply
 
Thread Tools
  #1  
Old 06-25-2007, 10:37 PM
Craig Walters's Avatar
Craig Walters Craig Walters is offline
Senior Member
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 8,786
Blog Entries: 4
Anyone know if this is a false positive?

anyone know if this file: ibhfcyte.exe is a virus or is my avg anti-virus giving me a false positive? i ask because even though this popped up with AVG, they dont list the thing in their virus encyclopedia/database and google has nothing on it either.

AVG says it's a 'Trojan horse downloader.Generic3XEN' . i've got so many automatic downloaders that i just cant tell if this is a legitimate file or a virus.
Reply With Quote top
  #2  
Old 06-26-2007, 02:07 AM
Doug Nelson's Avatar
Doug Nelson Doug Nelson is offline
Janitor
 
Join Date: Aug 2001
Posts: 7,068
Blog Entries: 21
Re: Anyone know if this is a false positive?

It gets zero google hits, so I definitely wouldn't trust it.
Reply With Quote top
  #3  
Old 06-26-2007, 03:54 AM
Cameraken's Avatar
Cameraken Cameraken is offline
Senior Member
 
Join Date: Feb 2005
Location: Lancashire (UK)
Posts: 1,158
Re: Anyone know if this is a false positive?

Hi Craig

This does sound like a random file name and is probably a bad file.
You may get more info by checking its properties (right click the file and click properties)

You can test the file at jotti or virustotal.
[*]Go to VirusTotal or Jotti's, and scan the following file(s).

ibhfcyte.exe
  • Click on the Browse button at the top of the screen.
  • Browse to the file.
  • Click OK.
  • Click Send, and the file will upload to VirusTotal / Jotti, where it will be scanned by several anti-virus programmes.
  • After a while, a window will open, with details of what the scans found.
  • Note details of any viruses found.

Ken.
Reply With Quote top
  #4  
Old 06-26-2007, 10:41 PM
Craig Walters's Avatar
Craig Walters Craig Walters is offline
Senior Member
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 8,786
Blog Entries: 4
Re: Anyone know if this is a false positive?

thanks, doug, ken.

this thing is quite weird. it's only 9kb and when i open windows explorer and go to windows, system32 to look at the file, when the file comes into view, the avg alert goes off. i dont have to click on anything or even mouse ever anything. all i have to do is see the file name in windows explorer and the alert goes off.

but, that's not even the strangest part. i decided to go to microsoft.com and see if they recognized it. i entered the file name into their search and it came up with nothing, but on the new results page of the search, avg once again went off seeing the name.

then, going down to the task bar and minimizing windows explorer or internet explorer and then maximizing either one again with that same name showing, avg would go off again.

quite odd.

oh, and i went to both of those sites, ken and both gave the same results, the file wouldnt upload so they couldnt analyze it.

and when the avg alert comes up, it gives me 4 options, ignore, info, heal or move to vault. when i click on info, it takes me to avg's encyclopedia. they have no knowledge of the file/virus.

when i try to open it in notepad, i'm denied because it's a 'system file'.

never seen a file act quite like this.
Reply With Quote top
  #5  
Old 06-27-2007, 12:42 AM
chillin's Avatar
chillin chillin is offline
Senior Member
 
Join Date: Sep 2006
Location: The Golden State
Posts: 1,324
Blog Entries: 1
Re: Anyone know if this is a false positive?

If this is only 9kb I would drop it into a notepad or text pad to see what is hidden inside. Could you send it to me? I'll try to play with it.
Reply With Quote top
  #6  
Old 06-27-2007, 01:14 AM
Craig Walters's Avatar
Craig Walters Craig Walters is offline
Senior Member
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 8,786
Blog Entries: 4
Re: Anyone know if this is a false positive?

Quote:
when i try to open it in notepad, i'm denied because it's a 'system file'.
sorry, chillin, tried that.
Reply With Quote top
  #7  
Old 06-27-2007, 03:52 AM
Photo678's Avatar
Photo678 Photo678 is offline
Senior Member
 
Join Date: May 2004
Posts: 328
Re: Anyone know if this is a false positive?

2 things, do a system search for the file name and try to find out what folder it is hiding itself in...that could give you an idea of what program it is attached to.

2nd thing.....go to your "run" command under the start menu, type "msconfig" without quotes, and click the startup tab....look through the list and try to spot that file, it will typically tell you what program is running that exe file.

basically, it IS a program that is running on your computer. My guess is some plugin that you recently installed.
Reply With Quote top
  #8  
Old 06-27-2007, 01:20 PM
Craig Walters's Avatar
Craig Walters Craig Walters is offline
Senior Member
 
Join Date: Apr 2005
Location: somewhere over there
Posts: 8,786
Blog Entries: 4
Re: Anyone know if this is a false positive?

photo678, it's in the system32 folder.

well, there's lots of programs in system32 that dont get run until you call something else up. the file is not in my startup list, at least not in the stuff that msconfig can see. the file has been there since january of this year, apparently.

i dont ever recall seeing that name come up in zone alarm asking for permissions and i dont recall win patrol ever asking about it either. it doesnt seem to be an active program. it's not denying me access to because of 'file in use'. it's just denying me access because it's a 'system file', or so it says. but microsoft has no knowledge of it and google has no knowledge of it and avg has no knowledge of it, even though the avg alerter is calling it a 'trojan horse downloader.generic3xen'. so, i dont know where it came from or if it's doing anything or associated with some other program. it may well be a legit file and associated with something i installed back in january of this year, but i cant tell.

i suppose i could isolate it to the avg virus vault and see if anything then fails to run. but i hate doing things like that blindly, with no knowledge of if this is legit or not.
Reply With Quote top
  #9  
Old 06-27-2007, 01:40 PM
Cameraken's Avatar
Cameraken Cameraken is offline
Senior Member
 
Join Date: Feb 2005
Location: Lancashire (UK)
Posts: 1,158
Re: Anyone know if this is a false positive?

Hi Craig.

That is often the effect of files in use and malware files that protect themself.
Try copying the files to some other place and submit them from there. If that does not work try the following:
  1. Go to Start > My Computer. Click the C drive. On the right side of the window please find Make a new folder and click it. Call it Cleanup
  2. Now download IceSword from http://www.majorgeeks.com/Icesword_d5199.html to a place where you can find it.
  3. Extract it to a place where you can find it.
  4. Once you have extracted it click on Icesword.exe to start the program.
    Next find the tab Files on the right side. Click it and it will open up an interface that looks like Windows Explorer.
  5. Navigate your way to >ibhfcyte.exe<
  6. Right click it and select "copy to". Send it to C:\Cleanup
  7. Next please submit C:\cleanup\bad File to be scanned by Jotti and/or by Virus Total.


Ken.
Reply With Quote top
  #10  
Old 06-27-2007, 01:48 PM
Gary Richardson's Avatar
Gary Richardson Gary Richardson is offline
Senior Member
 
Join Date: Mar 2004
Location: Yorkshire, England
Posts: 2,717
Re: Anyone know if this is a false positive?

Run a HJT scan and post the log back here Craig, there may be other items on your log that will give us a clue as to what your problem file is connected with.


Glad to see you've been reading Elrond's posts Ken.
Reply With Quote top
Reply

  RetouchPRO > Tools > Software


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
True or false Doug Nelson Salon 8 06-14-2007 03:07 AM
positive glass slides chrishoggy Image Help 6 11-25-2006 04:53 PM
Positive Film! Help me please! arcadhia Image Help 9 09-08-2006 11:55 PM
Worshipping False Gods! chris h Hardware 26 01-03-2005 09:01 AM
False Hope Toad Critiques 7 07-13-2003 11:52 AM


All times are GMT -6. The time now is 09:14 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
Copyright © 2016 Doug Nelson. All Rights Reserved