SageTV Community  

Go Back   SageTV Community > SageTV Products > SageTV Software
Forum Rules FAQs Community Downloads Today's Posts Search

Notices

SageTV Software Discussion related to the SageTV application produced by SageTV. Questions, issues, problems, suggestions, etc. relating to the SageTV software application should be posted here. (Check the descriptions of the other forums; all hardware related questions go in the Hardware Support forum, etc. And, post in the customizations forum instead if any customizations are active.)

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-06-2017, 10:19 AM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
Malware meltdown :-(

My long serving SageTV installation is having an issue.

I downloaded an executable I thought was trustworthy and which passed the viruis scan but the next thing was the computer announced it was going to restart without any cancel option.

When it came back up Kaspersky announced SageTVService had been infected with a trojan and deleted it..

After a full scan I tried to run the (archived somewhere) 7.1.9 installer to repair but it said fatal error and rolled back.

I then tried to uninstall and reinstall and it failed again.

I tried downloading the 7.1.9 setup.exe from https://forums.sagetv.com/forums/showthread.php?t=56137 and ran that installer.

Half way through Kaspersky decided this installer was infected and deleted it and rolled back any changes it had made causing the installer to fail half way through.

Now I cannot install/uninstall or repair.

SageTV installer keeps wanting to resume the previous install that Kaspersky rolled back all sorts of changes from.

Anybody know how I can reset and start setup again rather than resume setup or forcibly uninstall (SageTV is not listed in programs and features)


Michael
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #2  
Old 01-06-2017, 12:31 PM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
I finally got it to install after a reboot and the virus protection turned off.

However on starting virus protection Kaspersky started deleting components of the installation and registry settings.

It claims there is trojan e.g.

06.01.2017 14.57.11;Detected object (process memory) deleted.;d:\users\michael\downloads\sagetv_v7_1_9setup.exe;d:\users\michael\downloads\sagetv_v7_1_9setup.exe;PDM:Trojan.Win32.Generic;Other malware;01/06/2017 14:57:11

similar things reported with SageTV.exe and SageTVService.exe after installation.

So I'm running with virus protection off - which is a really dumb idea.

It just seems odd that its picked out SageTVService to be bad boy.
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #3  
Old 01-06-2017, 12:59 PM
stuckless's Avatar
stuckless stuckless is offline
SageTVaholic
 
Join Date: Oct 2007
Location: London, Ontario, Canada
Posts: 9,713
My guess, is that you still have a virus
Reply With Quote
  #4  
Old 01-06-2017, 02:10 PM
samgreco samgreco is offline
Sage Expert
 
Join Date: Jul 2004
Location: Villa Park, IL (Outside Chicago)
Posts: 617
I would highly recommend running ADWCleaner and probably the Junk Removal Tool. Both can be found at BleepingComputer.com, which is very safe.

I have had ADWCleaner find things nothing else can. It will ALWAYS reboot after a cleaning, so be prepared for that.

Also, it's probably not a bad idea to boot into safe mode to run either of these.

And ADWCleaner has solved probably upwards of 90% of malware issues that I have had on customer's PCs. Whether I knew they were there or not
Reply With Quote
  #5  
Old 01-06-2017, 02:28 PM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
Kaspersky full scan returned no threats.

It did that before but when SageTV got going it started deleting files and registry entries.

I am just trying malware bytes which apparently has found 45 threats two minutes into the scan oh 438 threats now

I'll try your suggestion for added peace of mind.

Thanks Michael
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #6  
Old 01-06-2017, 04:12 PM
trallyus trallyus is offline
Sage Aficionado
 
Join Date: Jul 2010
Posts: 392
Bitdefender did the same thing with sagetvclientsetup_9.0.4.232_rc1.000.exe
with virus name : Trojan.genericKD.3812987 and I marked it up as a false positive as it only marked it that way after a few updates to the virus signatures and I had the same thing happen with a game I installed as well from gog showing a false virus warning and only got it cleared up after I sent them the exe file to examine and they looked at it and cleared the file as good :P
Reply With Quote
  #7  
Old 01-07-2017, 07:52 AM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
Malware bytes just seems to stop so many files in...

Guess I'll try ADWCleaner
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #8  
Old 01-07-2017, 09:34 AM
SomeWhatLost's Avatar
SomeWhatLost SomeWhatLost is offline
Sage Expert
 
Join Date: Jan 2009
Location: earth
Posts: 532
I would suggest not installing malware on you sage server in the future...
it just never ends well...
__________________
NOTE: As one wise professional something once stated, I am ignorant & childish, with a mindset comparable to 9/11 troofers and wackjob conspiracy theorists. so don't take anything I say as advice...
Reply With Quote
  #9  
Old 01-08-2017, 08:54 AM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
FYI

http://www.nirsoft.net/utils/usb_devices_view.html

I downloaded the USBReview tool from the above website and then scanned with Kaspersky.

It said was it was clean but while running it popped up a dialog saying the PC was shutting down in 1 minute.

The troubles then began - so steer clear of nirsoft
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #10  
Old 01-08-2017, 09:19 AM
nyplayer nyplayer is offline
SageTVaholic
 
Join Date: Sep 2005
Posts: 4,997
If you can best to format and start with a clean Install and keep just the wiz.bin file.
__________________
Channels DVR UBUNTU Server 2 Primes 3 Connects TVE SageTV Docker with input from Channels DVR XMLTV and M3U VIA Opendct.
Reply With Quote
  #11  
Old 01-08-2017, 11:02 AM
EnterNoEscape's Avatar
EnterNoEscape EnterNoEscape is offline
SageTVaholic
 
Join Date: Jun 2010
Location: Harrisburg, PA
Posts: 2,657
Quote:
Originally Posted by nyplayer View Post
If you can best to format and start with a clean Install and keep just the wiz.bin file.
+1

As soon as I knew I had a malware/virus situation, I would have done exactly this. It's not worth the hours of scanning and uncertainty of if you really got everything.
__________________
SageTV v9 Server: ASRock Z97 Extreme4, Intel i7-4790K @ 4.4Ghz, 32GB RAM, 6x 3TB 7200rpm HD, 2x 5TB 7200rpm HD, 2x 6TB 7200rpm HD, 4x 256GB SSD, 4x 500GB SSD, unRAID Pro 6.7.2 (Dual Parity + SSD Cache).
Capture: 1x Ceton InfiniTV 4 (ClearQAM), 2x Ceton InfiniTV 6, 1x BM1000-HDMI, 1x BM3500-HDMI.

Clients: 1x HD300 (Living Room), 1x HD200 (Master Bedroom).
Software: OpenDCT :: WMC Live TV Tuner :: Schedules Direct EPG
Reply With Quote
  #12  
Old 01-08-2017, 12:52 PM
MattHelm MattHelm is offline
Sage Icon
 
Join Date: Jun 2005
Location: Chicago, IL
Posts: 1,209
Quote:
Originally Posted by michaeldjcox View Post
FYI

http://www.nirsoft.net/utils/usb_devices_view.html

I downloaded the USBReview tool from the above website and then scanned with Kaspersky.

It said was it was clean but while running it popped up a dialog saying the PC was shutting down in 1 minute.

The troubles then began - so steer clear of nirsoft
I use his software all the time, never had any issues. I'd trust it before I'd trust 99% of the anti-virus software. Way too may false positives to rely on that bad of code writers.
__________________
Server #1= AMD A10-5800, 8G RAM, F2A85-M PRO, 12TB, HDHomerun Prime, HDHR, Colossus (Playback - HD-200)
Server #2= AMD X2 3800+, 2G RAM, M2NPV-VM, 2TB, 3x HDHR OTA (Playback - HD-200)
Reply With Quote
  #13  
Old 01-08-2017, 12:57 PM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
Yeah think I'm getting close to that.

I managed to get a malwarebytes scan of my D drive to complete. .

If found two items to quanrantine and then wanted to restart.

I restarted and suddenly there was a windows update to apply (I turned off windows updating long ago)

Nows it back up and kaspersky came back on again.

It has not deleted anything but now pops up this dialog claiming sage is try to access a remote machine:

66.84.24.196 port 8018

Thats nothing to do with SageTV right?
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #14  
Old 01-08-2017, 01:09 PM
dealsdyker's Avatar
dealsdyker dealsdyker is offline
Sage Advanced User
 
Join Date: Dec 2006
Posts: 183
That site is sageTV (see here)
__________________
This space intentionally left blank
Reply With Quote
  #15  
Old 01-09-2017, 04:16 AM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
Yes you correct.

I think SageTV is a false positive.

None of the warnings kaspersky pops up turn out to be evil.

I must have had an bad update.

Malwarebytes found a few scary looking things during my scan that kaspersky has no problem with.

So hard to know what to trust.
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #16  
Old 01-09-2017, 11:04 AM
Taddeusz Taddeusz is offline
SageTVaholic
 
Join Date: Nov 2004
Location: Yukon, OK
Posts: 3,919
False positives is one of the huge glaring weaknesses of signature based detection.
__________________
Server: i5 8400, ASUS Prime H370M-Plus/CSM, 16GB RAM, 15TB drive array + 500GB cache, 2 HDHR's, SageTV 9, unRAID 6.6.3
Client 1: HD300 (latest FW), HDMI to an Insignia 65" 1080p LCD and optical SPDIF to a Sony Receiver
Client 2: HD200 (latest FW), HDMI to an Insignia NS-LCD42HD-09 1080p LCD
Reply With Quote
  #17  
Old 02-10-2017, 04:36 PM
Galaxysurfer Galaxysurfer is offline
Sage Aficionado
 
Join Date: Jun 2009
Location: Calgary, AB CANADA
Posts: 396
I too had my adventures with this program & KIS 2017 not playing nice so sent an incident to Kaspersky with links to software so hopefully this will be fixed once & for all.


Galaxysurfer
Reply With Quote
  #18  
Old 02-15-2017, 11:21 AM
michaeldjcox michaeldjcox is offline
Sage Fanatic
 
Join Date: Nov 2006
Location: Ipswich, Suffolk, United Kingdom
Posts: 829
Having thought about it a bit I seem to remember adding all the sage exes into the trusted apps list years ago.

I reckon an update from kaspersky must have cleared them off the list.
__________________
Web Feed Encoder developer
SageTV Catchup developer
Reply With Quote
  #19  
Old 02-17-2017, 04:08 AM
Galaxysurfer Galaxysurfer is offline
Sage Aficionado
 
Join Date: Jun 2009
Location: Calgary, AB CANADA
Posts: 396
Kaspersky detection fix

Informed Kaspersky of the problem & they came up with a fix. Dont know if issue is solved
since I chose not to use my license at renewal time & moved back to Eset which I know works fine with Sagetv. I like that it is easy to set custom rules for firewall communication between server & clients. So if you out there still want to use Kaspersky product it should work again.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
RC3 Client Meltdown Crowdx42 SageTV Beta Test Software 3 05-07-2004 02:42 PM


All times are GMT -6. The time now is 04:34 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2023, vBulletin Solutions Inc.
Copyright 2003-2005 SageTV, LLC. All rights reserved.