Virus Found [UPDATE: Unrelated to Moving Pictures] (1 Viewer)

fforde

Community Plugin Dev
June 7, 2007
2,667
1,702
44
Texas
Home Country
United States of America United States of America
Well according to the VirusTotal PDF you linked, this is a buffer overrun exploit from 2004. But I am trying to reproduce the issue by setting up the same movies on my test system using the same data providers, but all images that are downloaded for me are clean according to VirusTotal. I am not really sure what to do. If we could identify a malicious image on a web server we pull from, then we could alert the site owner. Moving Pictures also sometimes converts an image file to JPG format depending on the source, so I suppose it's possible that the Windows GDI library we use is creating in some cases malformed files.

Can you provide debug log files from when one of these image files is downloaded? To generate such files you'd have to try to recreate the same situation that caused the image files to be grabbed in the first place.
 

fforde

Community Plugin Dev
June 7, 2007
2,667
1,702
44
Texas
Home Country
United States of America United States of America
If it is in fact a malicious file on a web server then you should be able to delete all the covers from your covers folder for the given movie and re-retrieve artwork for that film. Because theoretically the same image files will be downloaded again, you should be reproducing the issue. If you can not consistently reproduce the issue this way, then it means either a bug in the image file writing logic in Moving Pictures, or the cause is something local on your machine.
 

TheWho

Portal Pro
December 26, 2008
67
1
Home Country
Sweden Sweden
fforde this is just a wild guess between you and me but couldn't it be a loadbalancing thing.... like... cover-loadbal-server1 got a non infected file but cover-loadbal-server2 got a infected file....

anyway..... i will try this later on today (its 16.50 here now...)
 

jameson_uk

Retired Team Member
  • Premium Supporter
  • January 27, 2005
    7,257
    2,533
    Birmingham
    Home Country
    United Kingdom United Kingdom
    I remember an MS vulnerability to do with jpg files several months ago.

    Could it be that your machine is infected by some other malware and this is trying to exploit this vulnerability each time you download a jpg?

    This particular vulnerability was patched in windows some months ago so your machine would only be at risk if you have not pactched in over six months. That said not ideal but have you tried downloading other images from the web and naming them in the same format as these?

    AIUI the actual exploit is in a header being set to 1 or 0 when the only allowable value is 2 so I doubt NOD is being as silly as looking at the name mask but could be....
     

    TheWho

    Portal Pro
    December 26, 2008
    67
    1
    Home Country
    Sweden Sweden
    jameson_uk i have almost never ever had any malware/spyware or virus/trojan/masks on my computer but to be 100% sure i will run anti-malware, spybot, ad-aware. (have already run a complete nod32 scan)
     

    Ratti3

    New Member
    November 20, 2009
    3
    0
    I get this too on one movie (Basic Instinct), I'm using Win 7 32, MP 1.0.2, MP 0.7.5, UK IMDB Scripts. Using Mcafee Ent 8.7
    Don't have access to logs atm.

    Edit: This is a brand new install of Windows.
    Edit 2: I will provide the logs later, I can recreate this everytime. Not near the HTPC at the moment, sorry.

    mcshite.jpg
     

    fforde

    Community Plugin Dev
    June 7, 2007
    2,667
    1,702
    44
    Texas
    Home Country
    United States of America United States of America
    Thanks for the additional feedback, but really can not help or investigate the issue unless someone posts a debug log file from when a bad image file is downloaded.

    Edited to be less of an ass. Sorry I was grumpy this morning. ><
     

    fforde

    Community Plugin Dev
    June 7, 2007
    2,667
    1,702
    44
    Texas
    Home Country
    United States of America United States of America
    Thanks for the log files Ratti3. What is happening is the windows logic we are using to save the image file to disk is failing. Based on the log files here, I cant know the exact nature of the error, simply that we call Image.Save(), a Windows function, the method then errors out, and we do not handle the error properly. We have actually added error handling for this in 1.0, so I think it no longer occurs with the new Beta. Can anyone confirm this? Has anyone seen this problem in Moving Pictures 1.0?

    If this is in fact the root of the problem, it would be possible to back port this fix to 0.7 while a 1.0 Stable is pending. I think we are just a week or two from a 1.0 Stable though so I am hesitant to do this back port. :/ Any thoughts?
     

    Users who are viewing this thread

    Similar threads

    i think info but I'm really not sure
    i think info but I'm really not sure
    When I import new films using Moving Pictures, it takes an incredibly long time for the information to be found and downloaded...
    Replies
    3
    Views
    757
    Just to be clear, I am talking about the GitHub access to the source code - using the Code button. I noticed that there is a link 'MediaPortal 1.36 Release' at the right-hand side of the page that takes me to page that has a link to the source code at the bottom of the page. That link seems to be virus free (according to Windows 10)...
    Just to be clear, I am talking about the GitHub access to the source code - using the Code button. I noticed that there is a link...
    I have tried to download the MediaPortal-1 of vs 1.36 source code and Windows 10 is saying it contains a virus. I have never had a...
    Replies
    1
    Views
    1K
    I've updated dlls in first post. Fixes: Summary / Overview was always empty Collections were not filtered to official ones Studios were not populated Fallback to english tagline didn't work Score / Popularity now empty instead of dummy rating and unknown popularity numbers Also I've tried to compile plugin against MP 1.34 x64 and...
    I've updated dlls in first post. Fixes: Summary / Overview was always empty Collections were not filtered to official ones Studios...
    Hi! TheTVDB.com has movies in their API now. API itself looks ok now so I decided to add TVDB to Moving Pictures. Check it if you...
    Replies
    2
    Views
    2K
    MP1 MP2 Design questions. DE
    No No
    No No
    Is there an xml display utility that will allow graphically checking of dialog and osd text and graphics element placement? or Is...
    Replies
    1
    Views
    2K
    I see no reason in Windows XP or 7, in my experience, on ancient Atom, Windows 10 worked faster than XP or 7...
    I see no reason in Windows XP or 7, in my experience, on ancient Atom, Windows 10 worked faster than XP or 7...
    Hi all, I'm new to MediaPortal and looking forward to using it. Just one catch and I apologize if it sounds silly - I want to run...
    Replies
    3
    Views
    2K
    Top Bottom