Jump to content

elmerFx

Recommended Posts

So, I click on Emby and get nothing. Start looking at the server logs and Bitdefender had this to say:

 

"The process C:\Users\User\AppData\Local\Temp\emby-server-updater\Emby.Server.Updater.exe manifests ransomware behavior and was blocked. Your files have been protected from being altered."

 

And it stopped Emby server. This just happened in the last few days. I'm on the beta path, so your code changed recently, or Bitdefender added a new code bit in its scanner. I set an exception and was able to reinstall Emby using admin rights. Odd. Very odd.

Link to comment
Share on other sites

Is there a link to submit a false positive to bitDefender?

 

The good news is that bitDefender is doing a good job of monitoring your system.

 

I was subject to Ransom Ware and it was a horrible experience.

Edited by chef
Link to comment
Share on other sites

The good news is that bitDefender is doing a good job of monitoring your system.

 

I was subject to Ransom Ware and it was a horrible experience.

I believe I remember that conversation here on the board, were you not on Avast to protect you? I just recently was reminded that my subscription with Avast was expiring Feb 15th. After some exchanges with Avast Support they wanted $135 for 3 years. Remembering the trouble with Avast that was discussed here and the posting in their forum and the answers from their fan boys, I ditched Avast and got BitDefender Total Security for $90 for 5 devices for 3 years and the transition was seamless and straight forward. Glad to hear that BitDefender is doing its job especially since I will stay on Win 7 for the near future.

Link to comment
Share on other sites

This is typical of many programs that see "update" programs that run behind the scenes showing up as "with ransomware like" behavior. Emby Server of course does download new versions and catalog items behind the scenes for you to help you keep the system updated (if options are set to do this).  This is an outstanding feature, but get produce those types of message.

 

If you downloaded your Emby Server software directly from the Emby Website or the software itself did the update then it's safe.

 

Unless you downloaded Emby Server from some 3rd party site you have nothing to worry about. Always download software from websites owned by the vendor and not from 3rd parties. This goes for all your software and isn't specific to Emby products.

 

With that said:

If in doubt and you want a bit more piece of mind, go to https://emby.media/download.html which is OUR OFFICIAL download page and download the appropriate version and install it over what you presently have.  If you do this and still get a "ransomware like" message it's just a false "positive" and can be ignored.

 

We have some very experience network people running Emby Server using very state of the art firewalls and IDS systems.  With the amount of users Emby has, if there was an actual problem the forums would be lit up with messages about it. :)

 

Carlo

Edited by cayars
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...