Question I downloaded syncplay from syncplay.pl and didnt scan the zipped file before extracting with 7zip, it said it cant complete extract because of virus.

dan1991Ro

Honorable
Oct 1, 2019
74
6
10,535
I downloaded syncplay from syncplay.pl and didnt scan the zipped file before extracting with 7zip, it said it cant complete extract because it has a malicious program. Ran it through virus total, a few vendors marked it as malicious, but only 3 unknown ones. Then the internet went out on my pc.
I ran defender on it and it said it's malicious and deleted it. I tried to download the zip again to put in another online virus scanner and it wouldnt work, the internet was shut off. I couldnt ping to google yet my win 11 said i am still online(ethernet hard line) but the connection is slowed. My phone had wifi though and another pc had internet. I restarted and all works fine. Could I have been infected? I didnt run anything from the zip and the extract never even completed. Ran a full scan with defender and it's all good But the internet shutting off had me worried. Plus I am pretty sure that syncplay apparently is pretty safe to use and it was prob a false positive. Or at least I would say that if the internet hadn't stopped working. What do you think? maybe defender shut off the internet when it saw I was trying to download the same internet file that was flagged as malicious?
These are the files I downloaded:

Syncplay 1.70 beta 1 portable


Syncplay 1.70 stable portable

Looked at the download history and this was it. Downloaded the 1.70 stable version twice. The beta 1 has 6 vendors flagging it as malicious. But none are important, apart from Mcaffee. And ofc win defender.

Also this:https://virusscan.jotti.org/en-US/filescanjob/ryiwb0c3k3 for 1.70 beta 1 portable

https://virusscan.jotti.org/en-US/filescanjob/olki1yha9r
https://www.virustotal.com/gui/file/9de4ba0318c8adbacf4aa8d9b18590463ca915f3e4b018aad71c415e4de64e06 syncplayserver.exe from 1.70 beta 1 portable

Virustotal finds dor syncplayserverse.exe 8 reds.
 
Regarding:

"My phone had wifi though and another pc had internet. I restarted and all works fine."

[My underline.]

Meaning that you restarted the problem PC - correct?

Take a look in Reliability History for any error codes, warnings, or even informational events just before or at the time internet connectivity was shut off.

You can use Event Viewer as well. However, Event Viewer requires more time and effort to figure out.

FYI:

How To - How to use Windows 10 Event Viewer | Tom's Hardware Forum (tomshardware.com)

My thought being that if malware is involved it was attempting to (and failed) to establish a connection to somewhere on the internet. Something crashed in the process....

Even if that is not what happened you may still find some other clue or clues via Reliability History and Event Viewer.
 
Regarding:

"My phone had wifi though and another pc had internet. I restarted and all works fine."

[My underline.]

Meaning that you restarted the problem PC - correct?

Take a look in Reliability History for any error codes, warnings, or even informational events just before or at the time internet connectivity was shut off.

You can use Event Viewer as well. However, Event Viewer requires more time and effort to figure out.

FYI:

How To - How to use Windows 10 Event Viewer | Tom's Hardware Forum (tomshardware.com)

My thought being that if malware is involved it was attempting to (and failed) to establish a connection to somewhere on the internet. Something crashed in the process....

Even if that is not what happened you may still find some other clue or clues via Reliability History and Event Viewer.
Name resolution for the name secure.gravatar.com timed out after none of the configured DNS servers responded. Client PID 8348.

Name resolution for the name test.steampowered.com timed out after none of the configured DNS servers responded. Client PID 5432.

The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Name resolution for the name secure.gravatar.com timed out after none of the configured DNS servers responded. Client PID 8348.

The access history in hive \??\C:\Users\alexm\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Offline downlevel migration succeeded.

Successfully scheduled Software Protection service for re-start at 2023-11-27T16:20:56Z. Reason: RulesEngine.

Updated Windows Defender status successfully to SECURITY_PRODUCT_STATE_ON.


these are some of the event viewer activity logs around that time.
Dk what they mean.
 
secure.gravatar.com
Gravatar - have you had any deliberate involvement with that service?

From a link that I found and not willing post:

"Gravatar stands for “globally recognized avatar” and is a popular service that enables platforms like WordPress and other web applications to display user profile photos."

Concerns about the posted findings.

By context and some Googling....

- Making changes from "demand start" (you) to "auto start" (something being done perhaps without your direct involvement or consent).

- The access history path led to where settings.dat launched Media Power Player which failed on my system due to an unsupported format. I could not see or clear anything. However some changes apparently happened / were made on your system.

- Offline download migration: not familar with the tool but not something I would expect to see. Will defer to others with direct knowledge. Google for details about what download migration is and how it is used.

- Software Protection Services scheduled for restart on November 26th. Does that mean the services have been stopped or disabled?

- SECURITY_PRODUCT_STATE_ON. Also problematic.

Barring other comments and suggestions I would consider the system to be infected.

It could be that the root cause was elimated but there are still side effects and other changes remaining.

Try running "dism" and "sfc /scannow". Either one or both may find and fix some things.

Overall, you should consider planning a for a full system wipe and reinstall.
 
Hi, Syncplay developer Etoh here. As you can see from my post at https://www.reddit.com/r/software/comments/3hyuju/syncplay_132_sync_media_players_for_video/ for example we've been around for a long time developing the software in our spare time.

Syncplay is free open source software build using GitHub Actions and it is clean. While Syncplay 1.7.0 Beta 1 was a beta build none of our users reported any connection issues with it. As such, the issues you had would have been a coincidence.

The latest version of Syncplay is now 1.7.1 and it is available from https://github.com/Syncplay/syncplay/releases/tag/v1.7.1

The reason it gets detected is just because we can't afford to pay loads of money for cryptographic keys to sign the software, and virus scanners generally flag up everything that is a bit niche as suspicious if it isn't signed. It's really annoying, as I end up spending nearly as much time reporting false positives to virus companies as I do developing the software. It can sometimes take more than a week for them to actually process the false positive report too, which causes unnecessary worry for our users. Still, when they respond they always confirm it was a false positive.

Unfortunately, the way many virus scanners work is that they have a manual list of known false positives, so rather than fixing the underlying issue that caused the false positive they just whitelist the specific executable. That unfortunately means that every time we release a new Syncplay version or a beta it often gets flagged again as the false positive we already had confirmed as a false positive in a previous version. To make it worse, there are so many different virus scanning companies that the chance of being marked by one random one that nobody has heard of ends up being quite high, and each one has a different way to get in touch with them and sometimes even finding where to contact can be a headache.

As Syncplay is open source, if you want to you can always run it directly from Python in line with the guidance at https://syncplay.pl/guide/install/ and https://syncplay.pl/about/development/ although it is a bit of a pain to get it to work.

Syncplay does not use up much bandwidth, and to to connect to the internet it just uses the standard Python Twisted library. You can read more about the protocol at: https://syncplay.pl/about/protocol/