Jump to content

Trojan on Installer


djlf

Recommended Posts

Guys, Emby sever wouldnt load with windows defender detecting malware after install of latest stale release.

Defender picked up Trojan:Win32/Fethar.B!cl , which it quarantined but server wouldnt start.

After switching defender off, emby installed ok and ran ok. Turn defender on and same result as above.

Is this a false positive? or something to worry about?

 

Link to comment
Share on other sites

Happy2Play

Yes it would be a false positive, wonder why I haven't seen this on the three machines I have Server on, only running Defender.

Link to comment
Share on other sites

Happy2Play

ESET/NOD32 and Avast are causing browser issue also so something is going on.

Link to comment
Share on other sites

Just after emby installed. i did a fresh install from website because my auto organise was playing up.

When i clicked on app it wouldnt start. So installed again at the end of which defender kicked in saying

it found malware which is the trojan. I restored it from quarantine and allowed it - now emby runs fine.

Link to comment
Share on other sites

Happy2Play

So this was a reinstall over an existing install or a new install, not that is should matter.

Link to comment
Share on other sites

Reinstall over existing install . Did it 3 times to be sure. Each time defender found malware Trojan as described

Link to comment
Share on other sites

Happy2Play

Can you post the version of Defender also.

 

Can't reproduce on my machine

56ff2ccfdfbc4_defender.jpg

Link to comment
Share on other sites

THX.1138

Installed Emby for the first time ever. Got a Defende popup about a trojan in mediabrowser.serverapplication.exe.  See screenshot.

Proces:

Installed Emby completely. The screen to configure Emby opened in browser. I waited a couple of minutes and got a popup.

5700e4323c9d0_embytrojan.png

 

Please advise.

Link to comment
Share on other sites

steveBCN

I'm getting exactly the same issue. Latest automatic server update triggers Windows Defender which removes it citing the same trojan mentioned above.

Link to comment
Share on other sites

Since we can't reproduce, if you could do some testing of running the beta installer that would be very helpful. I've gone back to just embedding ffmpeg into the application rather than having it download on first run. I think it is the downloading of ffmpeg that is often triggering a false positive. Thanks.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...