[solved] Windows Defender killed DirectShow dll (1 Viewer)

Eaglehawk

MP Donator
  • Premium Supporter
  • September 12, 2015
    28
    9
    50
    Home Country
    Australia Australia
    I'm pretty sure it's a false positive:

    TrojanSpy:Win32/Skeeyah.A!rfn

    C:\Program Files (x86)\Team MediaPortal\MP2-Client\Plugins\VideoPlayers\DirectShowWrapper.dll
     

    HTPCSourcer

    Retired Team Member
  • Premium Supporter
  • May 16, 2008
    11,418
    2,335
    Home Country
    Germany Germany
    I'm pretty sure it's a false positive:
    C:\Program Files (x86)\Team MediaPortal\MP2-Client\Plugins\VideoPlayers\DirectShowWrapper.dll
    Well, I am not. ;)

    I don't get an an alert here when explicitely testing the file with Defender. The file on my system is version 2.16.4.7790 with a size of 257 kB
     

    HTPCSourcer

    Retired Team Member
  • Premium Supporter
  • May 16, 2008
    11,418
    2,335
    Home Country
    Germany Germany
    OK, the latest available definitions (from today) trigger the same alert here. I did update this morning when the new definitions were not yet available.

    47 of 56 online scanners have no issue with it, the others suspect some keylogging elements. I believe that you can safely ignore the alert.
     

    Eaglehawk

    MP Donator
  • Premium Supporter
  • September 12, 2015
    28
    9
    50
    Home Country
    Australia Australia
    I agree, let's hope it doesn't kill too many MP2 installs :)
     

    JohnHind

    Portal Member
    August 3, 2013
    17
    4
    65
    Home Country
    United Kingdom United Kingdom
    I'm seeing this too - reluctant to just take a majority verdict of virus scanners particularly when reputible ones like Kaspersky are reporting it - maybe the others are just slower to update? Could MediaPortal team scan a known good version to confirm this is false positive? Maybe also publish a checksum so we can be sure this is not a targeted attack with someone slipping in a "ringer" file?
     

    JohnHind

    Portal Member
    August 3, 2013
    17
    4
    65
    Home Country
    United Kingdom United Kingdom
    @Eaglehawk - That is the hash of the file that EMSIsoft say is infected! I meant the hash of the file that MediaPortal team officially distribute and stand by as safe. If it is a false positive, the file will be the same, but if it is a ringer someone else has infiltrated after instalation, then it would be different and probably the same as the one EMSIsoft tested. However, for the record my copy of the file matches the EMSIsoft report.
     

    HTPCSourcer

    Retired Team Member
  • Premium Supporter
  • May 16, 2008
    11,418
    2,335
    Home Country
    Germany Germany
    @morpheus_xx ,

    I don't think that we have changed the file since we released Spring 16.

    Any comments?
     

    TiVo

    Portal Member
    June 6, 2016
    11
    0
    Fareham Hampshire UK
    Home Country
    Great Britain (UK) Great Britain (UK)
    I installed MP 2 for the first time from the official download over the last week.
    One as client / server to a 64 bit Windows 10 (upgrade from 7).
    One as a client to a 64 bit Windows 10 (upgrade from 7).
    One as a client to a 64 bit Windows 10 new purchase OEM.

    All three had Windows Defender quarantine C:\Program Files (x86)\Team MediaPortal\MP2-Client\Plugins\VideoPlayers\DirectShowWrapper.dll as above.
     

    Users who are viewing this thread

    Similar threads

    I avoid touching that system as long as it runs. Now that 2.4.1 seems to run again, I probably wait for the next issue.
    I avoid touching that system as long as it runs. Now that 2.4.1 seems to run again, I probably wait for the next issue.
    Hi, I have just upgraded from MP 2.2.2 to MP 2.4.1, and now the client won't start. I see the splash screen, and then it just...
    Replies
    3
    Views
    913
    Any other suggestions for this?
    Any other suggestions for this?
    I have Flirc and the Skip 1s remote sending volume +/- events. I prefer to rely on just the Windows volume control so in...
    Replies
    4
    Views
    540
    ??? :confused: Please, try with latest MP 1.33, not 1.30 and, all in debug logs to provide...
    ??? :confused: Please, try with latest MP 1.33, not 1.30 and, all in debug logs to provide...
    Hi Running MP1 - 1.39 for long while, no issues. 10th April [same time as 2024-KB5037036 Cumulative Update for .NET Framework...
    Replies
    4
    Views
    345
    Thanks, @morpheus_xx that's sorted it. (FYI There were no leftovers in Program Files). Sorry I'm not involved with the development of MP2 any more - I'm having to do something else (still voluntary) which takes up all of my time. Now working harder than before I retired!
    Thanks, @morpheus_xx that's sorted it. (FYI There were no leftovers in Program Files). Sorry I'm not involved with the...
    I just upgraded my mp2 install to the latest version from the website. The install seemed to go OK, and the TV configuration...
    Replies
    5
    Views
    1K
    Installing other software, especially MP1, which is partly sharing Tv service with MP2, can make everything worse. Please upload your debug log files, if you want to solve the issue.
    Installing other software, especially MP1, which is partly sharing Tv service with MP2, can make everything worse. Please upload...
    Before you create this bug report: Make sure that your system (Windows, codecs and drivers) is up to date, matching the...
    Replies
    6
    Views
    1K
    Top Bottom