home
products
contribute
download
documentation
forum
Home
Forums
New posts
Search forums
What's new
New posts
All posts
Latest activity
Members
Registered members
Current visitors
Donate
Log in
Register
What's new
Search
Search
Search titles only
By:
New posts
Search forums
Search titles only
By:
Menu
Log in
Register
Navigation
Install the app
Install
More options
Contact us
Close Menu
Forums
MediaPortal 1
Support
General Support
Playback Problems
Contact us
RSS
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Reply to thread
Message
<blockquote data-quote="MPKeith" data-source="post: 306917" data-attributes="member: 82758"><p>Hi Ray,</p><p></p><p></p><p></p><p>Note that ZA does not pick it up either, at least until internet radio/bass.dll is used and even then it is not an immediate change to malware - there seems to be a delay or it needs a reset or some other step to be performed. Using the popular web based VirusTotal.com service, only 3 of 36 current uptodate virus checkers think that <a href="https://svn.sourceforge.net/svnroot/mediaportal/trunk/mediaportal/MediaPortal.Base/bass.dll" target="_blank">https://svn.sourceforge.net/svnroot/mediaportal/trunk/mediaportal/MediaPortal.Base/bass.dll</a> is suspect. Report for base.dll (before it converts into ZA-identifiable malware):</p><p><a href="http://www.virustotal.com/analisis/63b962e68af82eba31f72f3a023ef62f" target="_blank">Virustotal. Suspicious File VIPRE.Suspicious Win32.Malware.gen (suspicious)</a></p><p>Note that ZA does not detect anything unusual at this stage.</p><p></p><p>I would normally consider this a false positive, and just move on.... but since I know its not and digging a little deeper:</p><p>"W32.Malware.Gen</p><p>6 Sep</p><p>W32.Malware.Gen is a generic detection for files or threats that are part of the Malware Group which has the <strong>capability to download and execute additional threat</strong> by exploiting software vulnerabilities.</p><p>http://www.precisesecurity.com/blogs/2007/09/06/w32malwaregen/"</p><p></p><p>So bass.dll has the capability to to download and execute additional threats. I agree it still does not mean much, many "respectable" programs can turn up this warning.</p><p></p><p></p><p></p><p>I agree that this is usually the most common explanation and I have taken as many steps as I can under various conditions on different machines to try and rule this out. Used new clean machines, safe modes w/wo networking, cleared windows restore archives and the all usual steps when tracking down these types of problems. Fortunately (or unfortunately <img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite1" alt=":)" title="Smile :)" loading="lazy" data-shortname=":)" /> as a computer scientist I have had a lot of experience in this area for many years now, so I am as confident as you can be with windows boxes that I am running tight security ship. That still does not mean I rule it out though - it is the most common cause especially if the infected dll/program can be guaranteed not to contain malware, backdoor and/or remote security vulnerability - which is why I raised the question of integrity.</p><p></p><p>If it is a trojan piggybacking on base.dll, then it is highly specialised and/or bass.dll has something it really likes unlike all other files on the infected machines. Assuming its a piggybacking trojan, then it is not infecting any other dll's or files over at least a 7 month window that this problem has been reoccurring. How about with other MP users who have experienced this security breach? It all started the same time that I started dabbling with MP's internet radio functions, how about others? If it is infecting other dll's on my machines then ZA can only detect it in base.dll but I consider this is highly unlikely. As a piggybacking trojan, it is not readily visible in the specialised thread/process list security monitors I have tried at the time base.dll is active, and no direct file modify access is being made to base.dll while its in use that I can find or see. For me at least, the full malware detection only strikes sometime after base.dll has been used in internet radio operations, and as mentioned a few time now it needs some other intermediate step - most likely MP release control of base.dll so it can be modified and/or a system reset but I have been so far unable to conclusively confirm what exactly. These points in combination were enough for me to stop and start asking harder questions about base.dll... even if this security breach does turn out to be a separate trojan infection of some sort only not detectable by any spyware scanner.</p><p></p><p>There are two other possibilities that have to seriously consider now (which is why I posted really):</p><p> 1) base.dll or some nearby closely related code is somehow remotely exploitable, contains buffer overrun vulnerabilities or something similar while there is remote internet radio access. Possible initiated externally by visiting a rouge a radio link or some other external to the machine means. I have only used internet radio to access radioparadise.com a well known widely used and "respected" station, and I have only ever used one of four access urls that they provided me (posted at end):</p><p>OR</p><p> 2) base.dll or related code is of malicious intent, and initiates malware installation over the top of itself by itself. This really need's some time consuming packet sniffing to confirm/rule this out, and I am not very experienced in this area of security.</p><p></p><p></p><p></p><p>I do not doubt Team-MP is not all above board or would do such a thing knowingly, otherwise I would not even be bothering to post or use MP. What I am saying is that I can't delve (easily) into bass.dll and related code to see what is going on to solve this problem, and I assume that Team Mediaportal developers cannot, either? The best programmers in the world have been known to accidently introduce security vulrabilities into their code. Even if bass.dll is rock solid, respectable and has secure code, there appears to be a good deal of other apparently proprietary and closed source code that could also be responsible:</p><p></p><p></p><p>any others?</p><p></p><p>Malicious intent by proprietary code suppliers cannot be ruled out. A quick search for online casino affiliate referrals show sizable revenue share offers: "We offer a genuine 25 - 35% of net revenue of any players you refer to us" etc. That's a big incentive for any struggling shareware shop to make some money on the side, especially in this economic climate. In this unlikely and unfortunate case, and if they are half decent programmers then they probably would use the common affiliate tactic of targeting markets by time, country/region and IP address ranges. Not everyone would get the problem showing up, and of those that do, not all of the time. Only one thing is certain so far: bass.dll is implicated either indirectly or directly in infecting some of our machines with malware, and (fortunately!) it does not appear to be a Mediaportal specific security vulnerability.</p><p></p><p>Four Radio Paradise access urls mentioned above:</p><p><a href="http://64.236.34.97:80/stream/1048" target="_blank">http://64.236.34.97:80/stream/1048</a></p><p><a href="http://scfire-dll0l-1.stream.aol.com:80/stream/1048" target="_blank">http://scfire-dll0l-1.stream.aol.com:80/stream/1048</a></p><p><a href="http://scfire-chi0l-1.stream.aol.com:80/stream/1048" target="_blank">http://scfire-chi0l-1.stream.aol.com:80/stream/1048</a></p><p><a href="http://scfire-nyk0l-1.stream.aol.com:80/stream/1048" target="_blank">http://scfire-nyk0l-1.stream.aol.com:80/stream/1048</a></p></blockquote><p></p>
[QUOTE="MPKeith, post: 306917, member: 82758"] Hi Ray, Note that ZA does not pick it up either, at least until internet radio/bass.dll is used and even then it is not an immediate change to malware - there seems to be a delay or it needs a reset or some other step to be performed. Using the popular web based VirusTotal.com service, only 3 of 36 current uptodate virus checkers think that [url]https://svn.sourceforge.net/svnroot/mediaportal/trunk/mediaportal/MediaPortal.Base/bass.dll[/url] is suspect. Report for base.dll (before it converts into ZA-identifiable malware): [url=http://www.virustotal.com/analisis/63b962e68af82eba31f72f3a023ef62f]Virustotal. Suspicious File VIPRE.Suspicious Win32.Malware.gen (suspicious)[/url] Note that ZA does not detect anything unusual at this stage. I would normally consider this a false positive, and just move on.... but since I know its not and digging a little deeper: "W32.Malware.Gen 6 Sep W32.Malware.Gen is a generic detection for files or threats that are part of the Malware Group which has the [B]capability to download and execute additional threat[/B] by exploiting software vulnerabilities. http://www.precisesecurity.com/blogs/2007/09/06/w32malwaregen/" So bass.dll has the capability to to download and execute additional threats. I agree it still does not mean much, many "respectable" programs can turn up this warning. I agree that this is usually the most common explanation and I have taken as many steps as I can under various conditions on different machines to try and rule this out. Used new clean machines, safe modes w/wo networking, cleared windows restore archives and the all usual steps when tracking down these types of problems. Fortunately (or unfortunately :) as a computer scientist I have had a lot of experience in this area for many years now, so I am as confident as you can be with windows boxes that I am running tight security ship. That still does not mean I rule it out though - it is the most common cause especially if the infected dll/program can be guaranteed not to contain malware, backdoor and/or remote security vulnerability - which is why I raised the question of integrity. If it is a trojan piggybacking on base.dll, then it is highly specialised and/or bass.dll has something it really likes unlike all other files on the infected machines. Assuming its a piggybacking trojan, then it is not infecting any other dll's or files over at least a 7 month window that this problem has been reoccurring. How about with other MP users who have experienced this security breach? It all started the same time that I started dabbling with MP's internet radio functions, how about others? If it is infecting other dll's on my machines then ZA can only detect it in base.dll but I consider this is highly unlikely. As a piggybacking trojan, it is not readily visible in the specialised thread/process list security monitors I have tried at the time base.dll is active, and no direct file modify access is being made to base.dll while its in use that I can find or see. For me at least, the full malware detection only strikes sometime after base.dll has been used in internet radio operations, and as mentioned a few time now it needs some other intermediate step - most likely MP release control of base.dll so it can be modified and/or a system reset but I have been so far unable to conclusively confirm what exactly. These points in combination were enough for me to stop and start asking harder questions about base.dll... even if this security breach does turn out to be a separate trojan infection of some sort only not detectable by any spyware scanner. There are two other possibilities that have to seriously consider now (which is why I posted really): 1) base.dll or some nearby closely related code is somehow remotely exploitable, contains buffer overrun vulnerabilities or something similar while there is remote internet radio access. Possible initiated externally by visiting a rouge a radio link or some other external to the machine means. I have only used internet radio to access radioparadise.com a well known widely used and "respected" station, and I have only ever used one of four access urls that they provided me (posted at end): OR 2) base.dll or related code is of malicious intent, and initiates malware installation over the top of itself by itself. This really need's some time consuming packet sniffing to confirm/rule this out, and I am not very experienced in this area of security. I do not doubt Team-MP is not all above board or would do such a thing knowingly, otherwise I would not even be bothering to post or use MP. What I am saying is that I can't delve (easily) into bass.dll and related code to see what is going on to solve this problem, and I assume that Team Mediaportal developers cannot, either? The best programmers in the world have been known to accidently introduce security vulrabilities into their code. Even if bass.dll is rock solid, respectable and has secure code, there appears to be a good deal of other apparently proprietary and closed source code that could also be responsible: any others? Malicious intent by proprietary code suppliers cannot be ruled out. A quick search for online casino affiliate referrals show sizable revenue share offers: "We offer a genuine 25 - 35% of net revenue of any players you refer to us" etc. That's a big incentive for any struggling shareware shop to make some money on the side, especially in this economic climate. In this unlikely and unfortunate case, and if they are half decent programmers then they probably would use the common affiliate tactic of targeting markets by time, country/region and IP address ranges. Not everyone would get the problem showing up, and of those that do, not all of the time. Only one thing is certain so far: bass.dll is implicated either indirectly or directly in infecting some of our machines with malware, and (fortunately!) it does not appear to be a Mediaportal specific security vulnerability. Four Radio Paradise access urls mentioned above: [url]http://64.236.34.97:80/stream/1048[/url] [url]http://scfire-dll0l-1.stream.aol.com:80/stream/1048[/url] [url]http://scfire-chi0l-1.stream.aol.com:80/stream/1048[/url] [url]http://scfire-nyk0l-1.stream.aol.com:80/stream/1048[/url] [/QUOTE]
Insert quotes…
Verification
Post reply
Forums
MediaPortal 1
Support
General Support
Playback Problems
Contact us
RSS
Top
Bottom