![]() |
|
SageTV Software Discussion related to the SageTV application produced by SageTV. Questions, issues, problems, suggestions, etc. relating to the SageTV software application should be posted here. (Check the descriptions of the other forums; all hardware related questions go in the Hardware Support forum, etc. And, post in the customizations forum instead if any customizations are active.) |
![]() |
|
Thread Tools | Search this Thread | Display Modes |
#1
|
||||
|
||||
Kaspersky: FraudTool.Win32.Spylocked.ds
Kaspersky just zapped ever SageTV client off of all of my computers claiming it was a virus.
Hit my computer and my son's computer at almost the same time, just a few minutes appart. Basically deleted SageTV and made us reboot. I tried to download the client again, but it deleted the download as soon as it was finished with the same virus claim! Hmmm... not happy. |
#2
|
|||
|
|||
http://www.securelist.com/en/descrip...2.SpyLocked.cx
Not sure if Kaspersky is actually responsible, sounds more like malware Grant |
#3
|
||||
|
||||
That was my first thought that it was malware infection that got sage. But how would malware infect a zip file that has the sage client in it? I didn't know malware could infect unopened zip files.
Also, Sage wasn't running on either of the desktops when Kaspersky flagged it. Edit: Yea, I can't even download it without it being flagged and deleted before I open it. Last edited by Serra; 11-18-2010 at 05:10 PM. |
#4
|
||||
|
||||
When was the last update to Kaspersky?
Maybe a bad DAT file Did you submit a sample to Kaspersky? Could be a false positive. I've had those before Also you might want to set an exception for the SageTV program file folder |
#5
|
|||
|
|||
Same problem here. SageTV was working fine yesterday and then today (after updates?) it suddenly is flagging SageTV.exe as a virus and deleting it.
You can restore it from the Quarantine window and add an exception =/ |
#6
|
|||
|
|||
Highly doubt it is a false positive.
My laptop crashed today when I tried to start client. I did full restore and kaspersky blocks it even while downloading. Sage should look in to it. I do not want to restore again! |
#7
|
||||
|
||||
I ran a couple of tests and Kaspersky 2010 and 2011 both prevent new downloads of the client. They are fine with the server, but not the client. As noted, the file will not even open on download, both version prevent it from opening at all.
It could be a false positive, but I don't think the file was infected at my end since PCs that are clean will not open the file. I can't find a way to flag it as ignore, since it isn't actually installed... Strange. Also, the client isn't in my quarantine. Looks like my version 2010 settings delete them rather than quarantine them. After a lot of looking around, I'm going with the idea I'm not infected. If I were infected and it was spreading across my network, then I'd expect it to show up in places that weren't SageTV Client files and SageTV downloads. I'm basically without Sage right now until a we can assure that this is a false positive. |
#8
|
||||
|
||||
I would give it a 98,999% certainty of false-positive. I have a standard procedure in cases like this. Download the latest versions. Did that now for both SageTV Client & SageTV Server. Installed them on a virtual machine. Copied out the following two files from virtual machine:
» SageTV.exe (from Server installation) » SageTVClient.exe (from Client installation) Then upload/ran them through VirusTotal web service: » SageTV.exe report (1 positive of 43 scanners - ClamAV) » SageTVClient.exe report (3 positive of 43 scanners - ClamAV, Kaspersky, Panda) This is a free web service with 43 virus/security products with up-to-date def/dat files. It scans the file you send through them all and gives a report. URL link in lines above. If I experienced this myself (using ESET Smart Security), I would log a false-positive request against my vendor. At the same time do re-analyzing on VirusTotal service as def/dat files are updated. See if the hit-rate gets larger. If suddenly I got 10, or more, positive hits. I would start to worry, look if hits are identifying common type, and find out what properties the thing identified has. With all the heuristic scanning going on in AV products, it is not uncommon getting false-positive these days. And boy is it fun when they even manage to make a false-positive on a vital Windows system file and quarantine it (McAfee vs. Intel). Guess McAfee probably downsize'd some QA process to increase margins ![]() ![]()
__________________
SageTV 7.1.9 (headless/service) • JavaRE 1.6.0_37 • 2x FloppyDTV C/CI (DVB-C) (fw: 1.2.10 B43110) (CAM: Conax) • Win7 x64 • Intel E3-1245V2 3.4GHz • 16GB PC3-10600 ECC • ASUS P8C WS (Intel C216) • APC Back-UPS RS 800 • STP-HD300 Extender (fw: beta 20110506 0) - HDMI/SPDIF - Yamaha RX-V2700 - HDMI - Sony KDL-52X2000 |
#9
|
||||
|
||||
Given that, I'd agree... now to figure out how to get Kaspersky to allow me to download it...
![]() |
#10
|
||||
|
||||
Not used Kaspersky myself. But isn't there a "temporary-disable" option on it ? Just to get the file downloaded. Install SageTV Client. Enable Kaspersky again. Figure out an exception rule on SageTV directory. And at that point, do a full virus scan on machine, just to see nothing slipped through.
__________________
SageTV 7.1.9 (headless/service) • JavaRE 1.6.0_37 • 2x FloppyDTV C/CI (DVB-C) (fw: 1.2.10 B43110) (CAM: Conax) • Win7 x64 • Intel E3-1245V2 3.4GHz • 16GB PC3-10600 ECC • ASUS P8C WS (Intel C216) • APC Back-UPS RS 800 • STP-HD300 Extender (fw: beta 20110506 0) - HDMI/SPDIF - Yamaha RX-V2700 - HDMI - Sony KDL-52X2000 |
#11
|
||||
|
||||
Quote:
|
#12
|
|||
|
|||
I got the same thing with ZoneAlarm. Then it quarantined it.
I'm surprised there aren't more complaints about it.
__________________
Intel E8400 Core 2 Duo, 2 GB RAM, nVidia GeForce 8400 GS, Hauppauge PVR-250 (SD), SiliconDust HDHomeRun, Windows XP MCE SP3, Motorola 6402, USB UIRT controlled |
#13
|
||||
|
||||
Quote:
![]()
__________________
Server: XP, SuperMicro X9SAE-V, i7 3770T, Thermalright Archon SB-E, 32GB Corsair DDR3, 2 x IBM M1015, Corsair HX1000W PSU, CoolerMaster CM Storm Stryker case Storage: 2 x Addonics 5-in-3 3.5" bays, 1 x Addonics 4-in-1 2.5" bay, 24TB Client: Windows 7 64-bit, Foxconn G9657MA-8EKRS2H, Core2Duo E6600, Zalman CNPS7500, 2GB Corsair, 320GB, HIS ATI 4650, Antec Fusion Tuners: 2 x HD-PVR (HTTP tuning), 2 x HDHR, USB-UIRT Software: SageTV 7 |
#14
|
||||
|
||||
Quote:
Your level of virus blocking really depends on what the PC is for. I don't have virus blockers on some of my PCs, don't need them. On my work PC and my son's PC, I use Kaspersky as it is the best I've found. I can't really take any chances with my work PC, if it goes down, I can't make a living. |
#15
|
||||
|
||||
Thanks for the info; we're contacting ZoneAlarm and Kaspersky about this. You can be 100% sure this is a false positive. There are no viruses in the software that we distribute.
__________________
Jeffrey Kardatzke Founder of SageTV |
#16
|
||||
|
||||
Thanks for confirming that for us. For anyone that lost their sagetv.exe file, just do a reinstall and say "Repair" and it will just put the file back without any other changes.
|
#17
|
|||
|
|||
This kind of thing is one reason why signature based A/V is outdated.
__________________
Server: i5 8400, ASUS Prime H370M-Plus/CSM, 16GB RAM, 15TB drive array + 500GB cache, 2 HDHR's, SageTV 9, unRAID 6.6.3 Client 1: HD300 (latest FW), HDMI to an Insignia 65" 1080p LCD and optical SPDIF to a Sony Receiver Client 2: HD200 (latest FW), HDMI to an Insignia NS-LCD42HD-09 1080p LCD |
#18
|
|||
|
|||
Quote:
I am sure it is Kaspersky while trying to clean it. The strange thing is sageclient.exe was already setup as a trusted application. Let us know in here when Kaspersky resolves the issue so I can install sageclient again. Last edited by impro; 11-19-2010 at 03:25 PM. |
#19
|
||||
|
||||
I have Symantec on one computer and Windows Essentials on two others and neither of them have had any issues.
__________________
hEdly ---------- SageTV 9, 64bit Hauppauge Quad AMD A6-3500; 8 GB RAM Gigabyte A75-UD4H MOBO Windows 10 Pro 64bit Receiving Free Over-the-Air HDTV in Sunny San Diego |
#20
|
||||
|
||||
Meh, yet another reason I don't waste my CPU resources with anti-virus software.. I mean, why NOT run every single IO process through 2 or 3 extra checks, that ultimately, will get defeated at some point.
__________________
Buy Fuzzy a beer! (Fuzzy likes beer) unRAID Server: i7-6700, 32GB RAM, Dual 128GB SSD cache and 13TB pool, with SageTVv9, openDCT, Logitech Media Server and Plex Media Server each in Dockers. Sources: HRHR Prime with Charter CableCard. HDHR-US for OTA. Primary Client: HD-300 through XBoxOne in Living Room, Samsung HLT-6189S Other Clients: Mi Box in Master Bedroom, HD-200 in kids room |
![]() |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Win32 Error | dasbwat | SageTV Software | 4 | 04-02-2011 12:46 PM |
Kaspersky problems with 6.4.6 & 6.4.7 | davidk21770 | SageTV Beta Test Software | 2 | 08-14-2008 06:36 AM |
SagetTVService Virus Win32.Agent.dwo | Ponchera | SageTV Software | 6 | 02-04-2008 06:33 PM |
using Win32 SendMessage call | esc67 | SageTV Software | 4 | 11-25-2003 08:25 PM |