Virus Found [UPDATE: Unrelated to Moving Pictures] (1 Viewer)

fforde

Community Plugin Dev
June 7, 2007
2,667
1,702
42
Texas
Home Country
United States of America United States of America
Well according to the VirusTotal PDF you linked, this is a buffer overrun exploit from 2004. But I am trying to reproduce the issue by setting up the same movies on my test system using the same data providers, but all images that are downloaded for me are clean according to VirusTotal. I am not really sure what to do. If we could identify a malicious image on a web server we pull from, then we could alert the site owner. Moving Pictures also sometimes converts an image file to JPG format depending on the source, so I suppose it's possible that the Windows GDI library we use is creating in some cases malformed files.

Can you provide debug log files from when one of these image files is downloaded? To generate such files you'd have to try to recreate the same situation that caused the image files to be grabbed in the first place.
 

fforde

Community Plugin Dev
June 7, 2007
2,667
1,702
42
Texas
Home Country
United States of America United States of America
If it is in fact a malicious file on a web server then you should be able to delete all the covers from your covers folder for the given movie and re-retrieve artwork for that film. Because theoretically the same image files will be downloaded again, you should be reproducing the issue. If you can not consistently reproduce the issue this way, then it means either a bug in the image file writing logic in Moving Pictures, or the cause is something local on your machine.
 

TheWho

Portal Pro
December 26, 2008
67
1
Home Country
Sweden Sweden
fforde this is just a wild guess between you and me but couldn't it be a loadbalancing thing.... like... cover-loadbal-server1 got a non infected file but cover-loadbal-server2 got a infected file....

anyway..... i will try this later on today (its 16.50 here now...)
 

jameson_uk

Retired Team Member
  • Premium Supporter
  • January 27, 2005
    7,258
    2,528
    Birmingham
    Home Country
    United Kingdom United Kingdom
    I remember an MS vulnerability to do with jpg files several months ago.

    Could it be that your machine is infected by some other malware and this is trying to exploit this vulnerability each time you download a jpg?

    This particular vulnerability was patched in windows some months ago so your machine would only be at risk if you have not pactched in over six months. That said not ideal but have you tried downloading other images from the web and naming them in the same format as these?

    AIUI the actual exploit is in a header being set to 1 or 0 when the only allowable value is 2 so I doubt NOD is being as silly as looking at the name mask but could be....
     

    TheWho

    Portal Pro
    December 26, 2008
    67
    1
    Home Country
    Sweden Sweden
    jameson_uk i have almost never ever had any malware/spyware or virus/trojan/masks on my computer but to be 100% sure i will run anti-malware, spybot, ad-aware. (have already run a complete nod32 scan)
     

    Ratti3

    New Member
    November 20, 2009
    3
    0
    I get this too on one movie (Basic Instinct), I'm using Win 7 32, MP 1.0.2, MP 0.7.5, UK IMDB Scripts. Using Mcafee Ent 8.7
    Don't have access to logs atm.

    Edit: This is a brand new install of Windows.
    Edit 2: I will provide the logs later, I can recreate this everytime. Not near the HTPC at the moment, sorry.

    mcshite.jpg
     

    fforde

    Community Plugin Dev
    June 7, 2007
    2,667
    1,702
    42
    Texas
    Home Country
    United States of America United States of America
    Thanks for the additional feedback, but really can not help or investigate the issue unless someone posts a debug log file from when a bad image file is downloaded.

    Edited to be less of an ass. Sorry I was grumpy this morning. ><
     

    fforde

    Community Plugin Dev
    June 7, 2007
    2,667
    1,702
    42
    Texas
    Home Country
    United States of America United States of America
    Thanks for the log files Ratti3. What is happening is the windows logic we are using to save the image file to disk is failing. Based on the log files here, I cant know the exact nature of the error, simply that we call Image.Save(), a Windows function, the method then errors out, and we do not handle the error properly. We have actually added error handling for this in 1.0, so I think it no longer occurs with the new Beta. Can anyone confirm this? Has anyone seen this problem in Moving Pictures 1.0?

    If this is in fact the root of the problem, it would be possible to back port this fix to 0.7 while a 1.0 Stable is pending. I think we are just a week or two from a 1.0 Stable though so I am hesitant to do this back port. :/ Any thoughts?
     

    Users who are viewing this thread

    Similar threads

    I have all of my media on a NAS. I guess it might just be a network issue, then.
    I have all of my media on a NAS. I guess it might just be a network issue, then.
    Whenever I go into the back end for Moving Pictures, it almost immediately hangs on the Movie Importer tab. If I want to go into...
    Replies
    4
    Views
    482
    MP1 MP2 Skin Properties DE
    Thanks RoChess. Somehow I always forget the web archive when looking for information that leads to dead links. :rolleyes:
    Thanks RoChess. Somehow I always forget the web archive when looking for information that leads to dead links. :rolleyes:
    Not sure if I’ve missed this info somewhere here but is there a full list or wiki that’s actually working with a full list of...
    Replies
    4
    Views
    858
    Yes, unfortunately, this would need a code change to support it. Next time I'm doing something on the plugin I'll try and remember to add support for this sort order.
    Yes, unfortunately, this would need a code change to support it. Next time I'm doing something on the plugin I'll try and...
    Hi, I was wondering if there is anyone who might be able to help me out. Is there a way to either use the sort feature and/or a...
    Replies
    6
    Views
    824
    OK, I found a way to make it work. It seems like MP-TV-series Configuration (and Moving Pictures Configuration) starts as Administrator, and the Administrator do not have yet logged in on the UNC \\192.168.222.247\Public even if the normal user on the PC have done it. So to fix it on the Win 11 HTPC: Created a shortcut to...
    OK, I found a way to make it work. It seems like MP-TV-series Configuration (and Moving Pictures Configuration) starts as...
    Hi! I was running MP1.33 x64 and I was fine and happy since many years, then the hard drive on the HTPC died. But I was able to...
    Replies
    1
    Views
    199
    Right, this solved this issue. I added my comment to this thread. Thank you very much!
    Right, this solved this issue. I added my comment to this thread. Thank you very much!
    Until MP 1.31 I was able to change the Videos home screen button to Moving Pictures: MediaPortal Configuration -> GUI -> Skin ->...
    Replies
    2
    Views
    604
    Top Bottom