|
SageTV Software Discussion related to the SageTV application produced by SageTV. Questions, issues, problems, suggestions, etc. relating to the SageTV software application should be posted here. (Check the descriptions of the other forums; all hardware related questions go in the Hardware Support forum, etc. And, post in the customizations forum instead if any customizations are active.) |
|
Thread Tools | Search this Thread | Display Modes |
#1
|
|||
|
|||
Malware meltdown :-(
My long serving SageTV installation is having an issue.
I downloaded an executable I thought was trustworthy and which passed the viruis scan but the next thing was the computer announced it was going to restart without any cancel option. When it came back up Kaspersky announced SageTVService had been infected with a trojan and deleted it.. After a full scan I tried to run the (archived somewhere) 7.1.9 installer to repair but it said fatal error and rolled back. I then tried to uninstall and reinstall and it failed again. I tried downloading the 7.1.9 setup.exe from https://forums.sagetv.com/forums/showthread.php?t=56137 and ran that installer. Half way through Kaspersky decided this installer was infected and deleted it and rolled back any changes it had made causing the installer to fail half way through. Now I cannot install/uninstall or repair. SageTV installer keeps wanting to resume the previous install that Kaspersky rolled back all sorts of changes from. Anybody know how I can reset and start setup again rather than resume setup or forcibly uninstall (SageTV is not listed in programs and features) Michael |
#2
|
|||
|
|||
I finally got it to install after a reboot and the virus protection turned off.
However on starting virus protection Kaspersky started deleting components of the installation and registry settings. It claims there is trojan e.g. 06.01.2017 14.57.11;Detected object (process memory) deleted.;d:\users\michael\downloads\sagetv_v7_1_9setup.exe;d:\users\michael\downloads\sagetv_v7_1_9setup.exe;PDM:Trojan.Win32.Generic;Other malware;01/06/2017 14:57:11 similar things reported with SageTV.exe and SageTVService.exe after installation. So I'm running with virus protection off - which is a really dumb idea. It just seems odd that its picked out SageTVService to be bad boy. |
#3
|
||||
|
||||
My guess, is that you still have a virus
__________________
Batch Metadata Tools (User Guides) - SageTV App (Android) - SageTV Plex Channel - My Other Android Apps - sagex-api wrappers - Google+ - Phoenix Renamer Downloads SageTV V9 | Android MiniClient |
#4
|
|||
|
|||
I would highly recommend running ADWCleaner and probably the Junk Removal Tool. Both can be found at BleepingComputer.com, which is very safe.
I have had ADWCleaner find things nothing else can. It will ALWAYS reboot after a cleaning, so be prepared for that. Also, it's probably not a bad idea to boot into safe mode to run either of these. And ADWCleaner has solved probably upwards of 90% of malware issues that I have had on customer's PCs. Whether I knew they were there or not |
#5
|
|||
|
|||
Kaspersky full scan returned no threats.
It did that before but when SageTV got going it started deleting files and registry entries. I am just trying malware bytes which apparently has found 45 threats two minutes into the scan oh 438 threats now I'll try your suggestion for added peace of mind. Thanks Michael |
#6
|
|||
|
|||
Bitdefender did the same thing with sagetvclientsetup_9.0.4.232_rc1.000.exe
with virus name : Trojan.genericKD.3812987 and I marked it up as a false positive as it only marked it that way after a few updates to the virus signatures and I had the same thing happen with a game I installed as well from gog showing a false virus warning and only got it cleared up after I sent them the exe file to examine and they looked at it and cleared the file as good :P |
#7
|
|||
|
|||
Malware bytes just seems to stop so many files in...
Guess I'll try ADWCleaner |
#8
|
||||
|
||||
I would suggest not installing malware on you sage server in the future...
it just never ends well...
__________________
NOTE: As one wise professional something once stated, I am ignorant & childish, with a mindset comparable to 9/11 troofers and wackjob conspiracy theorists. so don't take anything I say as advice... |
#9
|
|||
|
|||
FYI
http://www.nirsoft.net/utils/usb_devices_view.html I downloaded the USBReview tool from the above website and then scanned with Kaspersky. It said was it was clean but while running it popped up a dialog saying the PC was shutting down in 1 minute. The troubles then began - so steer clear of nirsoft |
#10
|
|||
|
|||
If you can best to format and start with a clean Install and keep just the wiz.bin file.
__________________
Channels DVR UBUNTU Server 2 Primes 3 Connects TVE SageTV Docker with input from Channels DVR XMLTV and M3U VIA Opendct. |
#11
|
||||
|
||||
Quote:
As soon as I knew I had a malware/virus situation, I would have done exactly this. It's not worth the hours of scanning and uncertainty of if you really got everything.
__________________
SageTV v9 Server: ASRock Z97 Extreme4, Intel i7-4790K @ 4.4Ghz, 32GB RAM, 6x 3TB 7200rpm HD, 2x 5TB 7200rpm HD, 2x 6TB 7200rpm HD, 4x 256GB SSD, 4x 500GB SSD, unRAID Pro 6.7.2 (Dual Parity + SSD Cache). Capture: 1x Ceton InfiniTV 4 (ClearQAM), 2x Ceton InfiniTV 6, 1x BM1000-HDMI, 1x BM3500-HDMI. Clients: 1x HD300 (Living Room), 1x HD200 (Master Bedroom). Software: OpenDCT :: WMC Live TV Tuner :: Schedules Direct EPG |
#12
|
|||
|
|||
Quote:
__________________
Server #1= AMD A10-5800, 8G RAM, F2A85-M PRO, 12TB, HDHomerun Prime, HDHR, Colossus (Playback - HD-200) Server #2= AMD X2 3800+, 2G RAM, M2NPV-VM, 2TB, 3x HDHR OTA (Playback - HD-200) |
#13
|
|||
|
|||
Yeah think I'm getting close to that.
I managed to get a malwarebytes scan of my D drive to complete. . If found two items to quanrantine and then wanted to restart. I restarted and suddenly there was a windows update to apply (I turned off windows updating long ago) Nows it back up and kaspersky came back on again. It has not deleted anything but now pops up this dialog claiming sage is try to access a remote machine: 66.84.24.196 port 8018 Thats nothing to do with SageTV right? |
#15
|
|||
|
|||
Yes you correct.
I think SageTV is a false positive. None of the warnings kaspersky pops up turn out to be evil. I must have had an bad update. Malwarebytes found a few scary looking things during my scan that kaspersky has no problem with. So hard to know what to trust. |
#16
|
|||
|
|||
False positives is one of the huge glaring weaknesses of signature based detection.
__________________
Server: i5 8400, ASUS Prime H370M-Plus/CSM, 16GB RAM, 15TB drive array + 500GB cache, 2 HDHR's, SageTV 9, unRAID 6.6.3 Client 1: HD300 (latest FW), HDMI to an Insignia 65" 1080p LCD and optical SPDIF to a Sony Receiver Client 2: HD200 (latest FW), HDMI to an Insignia NS-LCD42HD-09 1080p LCD |
#17
|
|||
|
|||
I too had my adventures with this program & KIS 2017 not playing nice so sent an incident to Kaspersky with links to software so hopefully this will be fixed once & for all.
Galaxysurfer |
#18
|
|||
|
|||
Having thought about it a bit I seem to remember adding all the sage exes into the trusted apps list years ago.
I reckon an update from kaspersky must have cleared them off the list. |
#19
|
|||
|
|||
Kaspersky detection fix
Informed Kaspersky of the problem & they came up with a fix. Dont know if issue is solved
since I chose not to use my license at renewal time & moved back to Eset which I know works fine with Sagetv. I like that it is easy to set custom rules for firewall communication between server & clients. So if you out there still want to use Kaspersky product it should work again. |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
RC3 Client Meltdown | Crowdx42 | SageTV Beta Test Software | 3 | 05-07-2004 02:42 PM |