I have 6131_1KEx1\ft.exe which is in my extenders directory for 6131 for 1K remotes.
Looks like it was made in 2004.
In the 2K extender for 6131 there is no such file. Nor in any other extenders.
Any idea what ft.exe was about?
Odd file in 6131 1K extender - please jog your memory
Moderator: Moderators
-
ElizabethD
- Advanced Member
- Posts: 2348
- Joined: Mon Feb 09, 2004 12:07 pm
Odd file in 6131 1K extender - please jog your memory
Liz
Tweeking 8910, HTPro/9811, C7-7800, 6131o, 6131n, AtlasOCAP-1056B01, RCA-RCRP05B and enjoying the ride
Tweeking 8910, HTPro/9811, C7-7800, 6131o, 6131n, AtlasOCAP-1056B01, RCA-RCRP05B and enjoying the ride
-
ElizabethD
- Advanced Member
- Posts: 2348
- Joined: Mon Feb 09, 2004 12:07 pm
There is a suspicion that this file contains backdoor trojan.
I don't think so, but I'm not well versed in security.
It is a file date-time editor done in cmd window.
Not needed really. Perhaps removing this file inside this extender zip file would make sense so future users (if any) wouldn'tget security alerts.
I don't think so, but I'm not well versed in security.
It is a file date-time editor done in cmd window.
Not needed really. Perhaps removing this file inside this extender zip file would make sense so future users (if any) wouldn'tget security alerts.
Liz
Tweeking 8910, HTPro/9811, C7-7800, 6131o, 6131n, AtlasOCAP-1056B01, RCA-RCRP05B and enjoying the ride
Tweeking 8910, HTPro/9811, C7-7800, 6131o, 6131n, AtlasOCAP-1056B01, RCA-RCRP05B and enjoying the ride
-
The Robman
- Site Owner
- Posts: 21886
- Joined: Fri Aug 01, 2003 9:37 am
- Location: Chicago, IL
- Contact:
I'm no extender expert, but I don't recall any of them coming with any sort of .exe file, so I would also be suspicious. Is this just in your copy, or are you saying that it's part of a file over here?
Rob
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
-
ElizabethD
- Advanced Member
- Posts: 2348
- Joined: Mon Feb 09, 2004 12:07 pm
I just downloaded the zip file which I'm sure is the same what's on my XP. Mike's last updates were Jan 6, 2006, with that ft file from 2004.
http://www.hifi-remote.com/forums/dload ... le_id=1692
and it does include ft.exe.
It all started with a EEK (emsisoft) scan I did on a directory copied from XP.
http://www.hifi-remote.com/forums/dload ... le_id=1692
and it does include ft.exe.
It all started with a EEK (emsisoft) scan I did on a directory copied from XP.
I followed up on Virus Total where 33 engines claim backdoor. My file's MD5 and SHA1 hashes match what VT examined. They also reported that it loads rpcrt4.dll. Well, on XP it didn't load any such thing when I tried it. I never saw or used it before, hence this thread.M:\JP1\Extenders\6131_1KEx1.zip -> ft.exe detected: Backdoor.Generic.220498 (B) [krnl.xmd]
M:\JP1\Extenders\6131_1KEx1\ft.exe detected: Backdoor.Generic.220498 (B) [krnl.xmd]
Liz
Tweeking 8910, HTPro/9811, C7-7800, 6131o, 6131n, AtlasOCAP-1056B01, RCA-RCRP05B and enjoying the ride
Tweeking 8910, HTPro/9811, C7-7800, 6131o, 6131n, AtlasOCAP-1056B01, RCA-RCRP05B and enjoying the ride
-
The Robman
- Site Owner
- Posts: 21886
- Joined: Fri Aug 01, 2003 9:37 am
- Location: Chicago, IL
- Contact:
Yeah, I read Mike's notes, there's no mention of ft.exe, so I have removed it from the zip file. Normally I'd say to ask Mike about it, but he last visited here back in 2015.
Here's some discussion that I found on the web:
https://discussions.apple.com/thread/4303162
Here's some discussion that I found on the web:
https://discussions.apple.com/thread/4303162
Rob
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!
www.hifi-remote.com
Please don't PM me with remote questions, post them in the forums so all the experts can help!