Jump to content

My anti-virus program is flagging some type of exploit in Emby?


Recommended Posts

musicmafia
Posted

Thanks. I have now run the UpnP test, the Windows File Sharing scan, Common Ports scan and "all service ports" scan and all results said I was stealth and passed. 

I am the only user for my Emby account and I only play my files locally at home and I have a password for login. There are no other users, so hopefully I am good to go? 

Thanks again!

musicmafia
Posted

WOW! I just read this. https://emby.media/support/articles/advisory-23-05.html ... Looks like a LOT has been going on the couple days I was M.I.A. Sounds like you guys have your hands full. Since Emby is still working fine for me, can I presume I wasn't affected or do ALL users need to make changes per the article?

seanbuff
Posted (edited)
18 minutes ago, musicmafia said:

Since Emby is still working fine for me, can I presume I wasn't affected or do ALL users need to make changes per the article?

For you own benefit, it's recommended you go through the advisory notice and check for any evidence of the files described in the article, then take the necessary actions if required.

Edited by seanbuff
words
  • Like 1
Posted

@musicmafiaIf you're not opening any external ports and you aren't allowing external connections then I think you're ok, but worth going through checking like @seanbuffsays just to be safe.

musicmafia
Posted

Thanks guys! Now, if I only knew what I was doing ;) About the only thing on that list that I understand is how to change my password. 

I can't seem to get past the first task. Where do I find  Emby's programdata folder? I can't find anything for Emby in my Program Files. 

And I'm completely lost once I get to the section called "Review your server machine for".

Clearly I'm clueless. Where is the Limitless drug when you need it?  ;) Hopefully I have more luck than skill. 

 

 

Posted
6 minutes ago, musicmafia said:

Thanks guys! Now, if I only knew what I was doing ;) About the only thing on that list that I understand is how to change my password. 

I can't seem to get past the first task. Where do I find  Emby's programdata folder? I can't find anything for Emby in my Program Files. 

And I'm completely lost once I get to the section called "Review your server machine for".

Clearly I'm clueless. Where is the Limitless drug when you need it?  ;) Hopefully I have more luck than skill. 

 

 

On windows usually C:\Users{user}\AppData\Roaming\Emby-Server

  • Thanks 1
musicmafia
Posted
14 hours ago, Luke said:

On windows usually C:\Users{user}\AppData\Roaming\Emby-Server

Thanks Luke!!! There it is! I checked all these folders below manually and searched the programdata folder via file explorer and I can't locate any files named helper or Embyhelper. Is that good or bad?

  • Delete the plugin .dll file, which comes as helper.dll and EmbyHelper.dll
    • Primary location is the plugins folder under Emby's programdata folder
    • Also look in cache and data subfolders

 

Posted
1 minute ago, musicmafia said:

Thanks Luke!!! There it is! I checked all these folders below manually and searched the programdata folder via file explorer and I can't locate any files named helper or Embyhelper. Is that good or bad?

  • Delete the plugin .dll file, which comes as helper.dll and EmbyHelper.dll
    • Primary location is the plugins folder under Emby's programdata folder
    • Also look in cache and data subfolders

 

As of now it appears you weren't impacted by this.

  • Thanks 1
musicmafia
Posted (edited)
7 minutes ago, Luke said:

As of now it appears you weren't impacted by this.

Again, many many THANKS! You and your team and everyone here are the BEST. Thanks so much for taking the time to help me and many others. I owe you many many beers. Cheers!

image.jpeg.3cc13083e929b4a6b51412ce751b8c90.jpeg

Edited by musicmafia
  • Haha 3
  • Thanks 1
  • 3 weeks later...
musicmafia
Posted (edited)

Well, this is weird. I just did a routine reboot of my PC and now Emby is not starting. The only error is from my browsers telling me: 

This site can’t be reached

localhost refused to connect.

Attempt to connect manually gives me:

"Connection Failure We're unable to connect to the selected server right now. Please ensure it is running and try again."

Emby not working on my TV either (I guess since it connects via the PC).

It seemed that I had not been impacted by the 5/25 bug, but I've never had Emby not open before. I checked my anti-virus logs and nothing flagged there since last month when I first posted this thread. 

I don't know how to access a log since I can't open the dashboard. 

Any help appreciated. Thanks.

Edited by musicmafia
Posted
10 minutes ago, musicmafia said:

Well, this is weird. I just did a routine reboot of my PC and now Emby is not starting. The only error is from my browsers telling me: 

This site can’t be reached

localhost refused to connect.

Attempt to connect manually gives me:

"Connection Failure We're unable to connect to the selected server right now. Please ensure it is running and try again."

Emby not working on my TV either (I guess since it connects via the PC).

It seemed that I had not been impacted by the 5/25 bug, but I've never had Emby not open before. I checked my anti-virus logs and nothing flagged there since last month when I first posted this thread. 

I don't know how to access a log since I can't open the dashboard. 

Any help appreciated. Thanks.

HI, are you sure Emby Server is started? Try starting the server application. If there's still an issue, then please provide the info requested in:

Thanks.

musicmafia
Posted
3 minutes ago, Luke said:

HI, are you sure Emby Server is started? Try starting the server application. If there's still an issue, then please provide the info requested in:

Thanks.

UPDATE: IT'S WORKING!!!

Thanks Luke. It usually starts when I turn on my PC. I also tried manually starting and nothing was working. For the heck of it I tried rebooting AGAIN and when my PC booted up, I got a Microsoft alert, saying I needed to "fix" a problem (basically wanting me to sign in again and resubmit my pin). Once I did that, Emby popped right up!!!!

IT'S WORKING! Wish all fixes were that easy. Sorry to bump this old thread, but I got paranoid I guess ;) 

image.png.19c965cec5e231d9c1a801ed88ccdfdd.png

THANKS AS ALWAYS! 

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...