SageTV Community  

Go Back   SageTV Community > SageTV Products > SageTV Software
Forum Rules FAQs Community Downloads Today's Posts Search

Notices

SageTV Software Discussion related to the SageTV application produced by SageTV. Questions, issues, problems, suggestions, etc. relating to the SageTV software application should be posted here. (Check the descriptions of the other forums; all hardware related questions go in the Hardware Support forum, etc. And, post in the customizations forum instead if any customizations are active.)

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 11-18-2010, 03:47 PM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
Kaspersky: FraudTool.Win32.Spylocked.ds

Kaspersky just zapped ever SageTV client off of all of my computers claiming it was a virus.

Hit my computer and my son's computer at almost the same time, just a few minutes appart. Basically deleted SageTV and made us reboot. I tried to download the client again, but it deleted the download as soon as it was finished with the same virus claim!

Hmmm... not happy.
Reply With Quote
  #2  
Old 11-18-2010, 04:02 PM
OneOfMany OneOfMany is offline
Sage Aficionado
 
Join Date: Apr 2009
Location: Winnipeg
Posts: 374
http://www.securelist.com/en/descrip...2.SpyLocked.cx

Not sure if Kaspersky is actually responsible, sounds more like malware

Grant
Reply With Quote
  #3  
Old 11-18-2010, 04:17 PM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
That was my first thought that it was malware infection that got sage. But how would malware infect a zip file that has the sage client in it? I didn't know malware could infect unopened zip files.

Also, Sage wasn't running on either of the desktops when Kaspersky flagged it.

Edit: Yea, I can't even download it without it being flagged and deleted before I open it.

Last edited by Serra; 11-18-2010 at 05:10 PM.
Reply With Quote
  #4  
Old 11-18-2010, 06:37 PM
barney B.A.'s Avatar
barney B.A. barney B.A. is offline
Sage Advanced User
 
Join Date: May 2010
Location: South of Baltimore
Posts: 123
When was the last update to Kaspersky?
Maybe a bad DAT file
Did you submit a sample to Kaspersky?
Could be a false positive. I've had those before

Also you might want to set an exception for the SageTV program file folder
Reply With Quote
  #5  
Old 11-18-2010, 07:27 PM
Entz Entz is offline
New Member
 
Join Date: Feb 2009
Posts: 2
Same problem here. SageTV was working fine yesterday and then today (after updates?) it suddenly is flagging SageTV.exe as a virus and deleting it.

You can restore it from the Quarantine window and add an exception =/
Reply With Quote
  #6  
Old 11-19-2010, 05:52 AM
impro impro is offline
Sage Aficionado
 
Join Date: May 2006
Posts: 268
Highly doubt it is a false positive.
My laptop crashed today when I tried to start client.
I did full restore and kaspersky blocks it even while downloading.
Sage should look in to it.
I do not want to restore again!
Reply With Quote
  #7  
Old 11-19-2010, 06:33 AM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
I ran a couple of tests and Kaspersky 2010 and 2011 both prevent new downloads of the client. They are fine with the server, but not the client. As noted, the file will not even open on download, both version prevent it from opening at all.

It could be a false positive, but I don't think the file was infected at my end since PCs that are clean will not open the file. I can't find a way to flag it as ignore, since it isn't actually installed... Strange.

Also, the client isn't in my quarantine. Looks like my version 2010 settings delete them rather than quarantine them.

After a lot of looking around, I'm going with the idea I'm not infected. If I were infected and it was spreading across my network, then I'd expect it to show up in places that weren't SageTV Client files and SageTV downloads.

I'm basically without Sage right now until a we can assure that this is a false positive.
Reply With Quote
  #8  
Old 11-19-2010, 06:35 AM
voidpt's Avatar
voidpt voidpt is offline
Sage Aficionado
 
Join Date: Jan 2006
Location: Norway
Posts: 296
I would give it a 98,999% certainty of false-positive. I have a standard procedure in cases like this. Download the latest versions. Did that now for both SageTV Client & SageTV Server. Installed them on a virtual machine. Copied out the following two files from virtual machine:
» SageTV.exe (from Server installation)
» SageTVClient.exe (from Client installation)

Then upload/ran them through VirusTotal web service:
» SageTV.exe report (1 positive of 43 scanners - ClamAV)
» SageTVClient.exe report (3 positive of 43 scanners - ClamAV, Kaspersky, Panda)
This is a free web service with 43 virus/security products with up-to-date def/dat files. It scans the file you send through them all and gives a report. URL link in lines above.

If I experienced this myself (using ESET Smart Security), I would log a false-positive request against my vendor. At the same time do re-analyzing on VirusTotal service as def/dat files are updated. See if the hit-rate gets larger. If suddenly I got 10, or more, positive hits. I would start to worry, look if hits are identifying common type, and find out what properties the thing identified has.

With all the heuristic scanning going on in AV products, it is not uncommon getting false-positive these days. And boy is it fun when they even manage to make a false-positive on a vital Windows system file and quarantine it (McAfee vs. Intel). Guess McAfee probably downsize'd some QA process to increase margins Talk about return on investment
__________________
SageTV 7.1.9 (headless/service) JavaRE 1.6.0_37 2x FloppyDTV C/CI (DVB-C) (fw: 1.2.10 B43110) (CAM: Conax) Win7 x64 Intel E3-1245V2 3.4GHz 16GB PC3-10600 ECC ASUS P8C WS (Intel C216) APC Back-UPS RS 800 STP-HD300 Extender (fw: beta 20110506 0) - HDMI/SPDIF - Yamaha RX-V2700 - HDMI - Sony KDL-52X2000
Reply With Quote
  #9  
Old 11-19-2010, 06:42 AM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
Quote:
Originally Posted by voidpt View Post
I would give it a 98,999% certainty of false-positive.
Given that, I'd agree... now to figure out how to get Kaspersky to allow me to download it...
Reply With Quote
  #10  
Old 11-19-2010, 07:14 AM
voidpt's Avatar
voidpt voidpt is offline
Sage Aficionado
 
Join Date: Jan 2006
Location: Norway
Posts: 296
Quote:
Originally Posted by Serra View Post
how to get Kaspersky to allow me to download it...
Not used Kaspersky myself. But isn't there a "temporary-disable" option on it ? Just to get the file downloaded. Install SageTV Client. Enable Kaspersky again. Figure out an exception rule on SageTV directory. And at that point, do a full virus scan on machine, just to see nothing slipped through.
__________________
SageTV 7.1.9 (headless/service) JavaRE 1.6.0_37 2x FloppyDTV C/CI (DVB-C) (fw: 1.2.10 B43110) (CAM: Conax) Win7 x64 Intel E3-1245V2 3.4GHz 16GB PC3-10600 ECC ASUS P8C WS (Intel C216) APC Back-UPS RS 800 STP-HD300 Extender (fw: beta 20110506 0) - HDMI/SPDIF - Yamaha RX-V2700 - HDMI - Sony KDL-52X2000
Reply With Quote
  #11  
Old 11-19-2010, 07:20 AM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
Quote:
Originally Posted by voidpt View Post
Not used Kaspersky myself. But isn't there a "temporary-disable" option on it ? Just to get the file downloaded. Install SageTV Client. Enable Kaspersky again. Figure out an exception rule on SageTV directory. And at that point, do a full virus scan on machine, just to see nothing slipped through.
Yes, I downloaded it with it disabled. Then I set the sage folder as an exception. That seems to have done the trick. As far as I can tell, there is no way to download it without disabling Kaspersky!
Reply With Quote
  #12  
Old 11-19-2010, 09:35 AM
Zone99 Zone99 is offline
Sage User
 
Join Date: Nov 2008
Posts: 30
I got the same thing with ZoneAlarm. Then it quarantined it.

I'm surprised there aren't more complaints about it.
__________________
Intel E8400 Core 2 Duo, 2 GB RAM, nVidia GeForce 8400 GS, Hauppauge PVR-250 (SD), SiliconDust HDHomeRun, Windows XP MCE SP3, Motorola 6402, USB UIRT controlled
Reply With Quote
  #13  
Old 11-19-2010, 10:22 AM
Skirge01's Avatar
Skirge01 Skirge01 is offline
SageTVaholic
 
Join Date: Jun 2007
Location: New Jersey
Posts: 2,599
Quote:
Originally Posted by Zone99 View Post
I got the same thing with ZoneAlarm. Then it quarantined it.

I'm surprised there aren't more complaints about it.
We're tech savvy, we don't need to stinking anti-virus. In all seriousness, I usually don't on computers only I use, but on my SageTV client, I moved away from ZoneAlarm many years ago and I never cared for Kaspersky. I used AVG for quite some time, but moved away from that, as well, a number of years ago. At this point in time, I'm using MS Security Essentials and it works fine.
__________________
Server: XP, SuperMicro X9SAE-V, i7 3770T, Thermalright Archon SB-E, 32GB Corsair DDR3, 2 x IBM M1015, Corsair HX1000W PSU, CoolerMaster CM Storm Stryker case
Storage: 2 x Addonics 5-in-3 3.5" bays, 1 x Addonics 4-in-1 2.5" bay, 24TB
Client: Windows 7 64-bit, Foxconn G9657MA-8EKRS2H, Core2Duo E6600, Zalman CNPS7500, 2GB Corsair, 320GB, HIS ATI 4650, Antec Fusion
Tuners: 2 x HD-PVR (HTTP tuning), 2 x HDHR, USB-UIRT
Software: SageTV 7
Reply With Quote
  #14  
Old 11-19-2010, 10:32 AM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
Quote:
Originally Posted by Skirge01 View Post
We're tech savvy, we don't need to stinking anti-virus. In all seriousness, I usually don't on computers only I use, but on my SageTV client, I moved away from ZoneAlarm many years ago and I never cared for Kaspersky. I used AVG for quite some time, but moved away from that, as well, a number of years ago. At this point in time, I'm using MS Security Essentials and it works fine.
Yea, I liked ZA back in the day, but it simply became too disruptive and I moved to a hardware firewall.

Your level of virus blocking really depends on what the PC is for. I don't have virus blockers on some of my PCs, don't need them. On my work PC and my son's PC, I use Kaspersky as it is the best I've found.

I can't really take any chances with my work PC, if it goes down, I can't make a living.
Reply With Quote
  #15  
Old 11-19-2010, 12:58 PM
Narflex's Avatar
Narflex Narflex is offline
Sage
 
Join Date: Feb 2003
Location: Redondo Beach, CA
Posts: 6,349
Thanks for the info; we're contacting ZoneAlarm and Kaspersky about this. You can be 100% sure this is a false positive. There are no viruses in the software that we distribute.
__________________
Jeffrey Kardatzke
Google
Founder of SageTV
Reply With Quote
  #16  
Old 11-19-2010, 02:38 PM
Serra's Avatar
Serra Serra is offline
Sage Advanced User
 
Join Date: Feb 2008
Posts: 156
Thanks for confirming that for us. For anyone that lost their sagetv.exe file, just do a reinstall and say "Repair" and it will just put the file back without any other changes.
Reply With Quote
  #17  
Old 11-19-2010, 03:03 PM
Taddeusz Taddeusz is offline
SageTVaholic
 
Join Date: Nov 2004
Location: Yukon, OK
Posts: 3,919
This kind of thing is one reason why signature based A/V is outdated.
__________________
Server: i5 8400, ASUS Prime H370M-Plus/CSM, 16GB RAM, 15TB drive array + 500GB cache, 2 HDHR's, SageTV 9, unRAID 6.6.3
Client 1: HD300 (latest FW), HDMI to an Insignia 65" 1080p LCD and optical SPDIF to a Sony Receiver
Client 2: HD200 (latest FW), HDMI to an Insignia NS-LCD42HD-09 1080p LCD
Reply With Quote
  #18  
Old 11-19-2010, 03:22 PM
impro impro is offline
Sage Aficionado
 
Join Date: May 2006
Posts: 268
Quote:
Originally Posted by Narflex View Post
Thanks for the info; we're contacting ZoneAlarm and Kaspersky about this. You can be 100% sure this is a false positive. There are no viruses in the software that we distribute.
I am not saying that sage froze my computer.
I am sure it is Kaspersky while trying to clean it.
The strange thing is sageclient.exe was already setup as a trusted application.

Let us know in here when Kaspersky resolves the issue so I can install sageclient again.

Last edited by impro; 11-19-2010 at 03:25 PM.
Reply With Quote
  #19  
Old 11-19-2010, 07:48 PM
hedly's Avatar
hedly hedly is offline
Sage Advanced User
 
Join Date: Feb 2008
Location: San Diego
Posts: 192
I have Symantec on one computer and Windows Essentials on two others and neither of them have had any issues.
__________________
hEdly
----------
SageTV 9, 64bit
Hauppauge Quad
AMD A6-3500; 8 GB RAM
Gigabyte A75-UD4H MOBO
Windows 10 Pro 64bit
Receiving Free Over-the-Air HDTV in Sunny San Diego
Reply With Quote
  #20  
Old 11-20-2010, 01:55 AM
Fuzzy's Avatar
Fuzzy Fuzzy is offline
SageTVaholic
 
Join Date: Sep 2005
Location: Jurupa Valley, CA
Posts: 9,957
Meh, yet another reason I don't waste my CPU resources with anti-virus software.. I mean, why NOT run every single IO process through 2 or 3 extra checks, that ultimately, will get defeated at some point.
__________________
Buy Fuzzy a beer! (Fuzzy likes beer)

unRAID Server: i7-6700, 32GB RAM, Dual 128GB SSD cache and 13TB pool, with SageTVv9, openDCT, Logitech Media Server and Plex Media Server each in Dockers.
Sources: HRHR Prime with Charter CableCard. HDHR-US for OTA.
Primary Client: HD-300 through XBoxOne in Living Room, Samsung HLT-6189S
Other Clients: Mi Box in Master Bedroom, HD-200 in kids room
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Win32 Error dasbwat SageTV Software 4 04-02-2011 12:46 PM
Kaspersky problems with 6.4.6 & 6.4.7 davidk21770 SageTV Beta Test Software 2 08-14-2008 06:36 AM
SagetTVService Virus Win32.Agent.dwo Ponchera SageTV Software 6 02-04-2008 06:33 PM
using Win32 SendMessage call esc67 SageTV Software 4 11-25-2003 08:25 PM


All times are GMT -6. The time now is 07:31 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2023, vBulletin Solutions Inc.
Copyright 2003-2005 SageTV, LLC. All rights reserved.