Ransomware Launched By PLEX?

Server Version#:Can’t Get
Player Version#:Can’t Get
Just had my virus scanner tell me that Plex Server, when it launched, pulled up some ransom code. File it trapped was PLEX MEDIA SERVICES.exe. Very concerned, have a screen shot if it would help. ???

More Info:

Name: Plex Media Server.exe
From: Plex, Inc.
Version: 1.19.4.2865
Copyright: Copyright © 2014
Detected Resource or Process ID: C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
Response: Terminated
Changed Files: 1eba901bf14d9c5928a8e65f30545205639b3e14.jpg.tmp.3750312f-dee9-4293-9aaf-b546e8d4cbc0

2f30946e05283a20c9623b9b44a2c9abbf3d301d.jpg.tmp.9b3ff835-a8dc-42ec-8b15-55a2ff22316c

eafc89ca09b4591d49e0d319bfe71c30dbc9f2fd.jpg.tmp.e87e3c7b-8dd6-44b9-8dbc-bf4653bcafec|

Very likely a “false positive”. What is your anti virus software?

Submit the file to https://www.virustotal.com/gui/home/upload
and see how many other anti virus tools agree on the assessment, that Plex Server is a ransomware.

Done…

And? What do they say?

No idea what you are referring to. Anyway, reinstalled plex server and it came up, after restarting, without problems. Prior to reinstalling I had no access to any of my local files apparently because trend blocked them to protect the computer from whatever it was, now trend has no problem with the new files installed using the repair option in the installer. Definitely a novice at this stuff, but seems like there must have been something there for some reason. Been running trend for 6 years now without a problem and it has, on several occasions, found this stuff with other applications. Not an advertisement, just facts. Thanks.

I rechecked that upload link and I did not understand what it was you wanted uploaded. The file that would need to be analyzed to see if it had a virus is probably on the computer in a vault somewhere but I have no idea where it is, something more tuned to an expert in systems than a user like myself. Thanks.

The virustotal site will also accept a URL to the server from where this softwware was downloaded. In this case that would be in the ‘Downloads’ section of plex.tv
https://downloads.plex.tv/plex-media-server-new/1.19.4.2865-4fa317f77/windows/PlexMediaServer-1.19.4.2865-4fa317f77-x86.exe

But anyway: that anti virus software is falsely classifying totally legit software as a virus, does happen from time to time.
This is usually solved by reporting the file to the manufacturer of the anti virus software. Many anti virus softwares already have this procedure automated, so that you often only have to wait a few hours until the next software update of the anti virus package arrives.
I assume this is what happened on your computer as well.
The software somehow detected a virusand locked it up.
At the same time it reported the file to its manufaturer, who analyzed it and then produced a software updated which resolved the wrong detection.

It could be just a name coincidence.
There is a PLEX ransomware.
https://www.pcrisk.com/removal-guides/17173-plex-ransomware

Appreciate all the help, seems to be fixed with the repair. My belief is that one false positive is better than any number of false negatives. With all the stuff on our computers now-a-days, having to recover from something like this getting through is nothing short of a nightmare. That’s also why I have three computers, all identical, anyone of which can be fired up if the currently used computer gets screwed up, Only job is, every once a month I have to fire them all up to make sure they are current with trend and windows, but worth the work. Harkins back to the days when a screwed up computer cost me jobs. Thanks again.

If you don’t hang out in Hong Kong Goat Porn sites you probably don’t need anything more Zealous than Windows Defender - and I’ve never had WD claim Plex was a virus.

It could happen - hasn’t yet.

2 Likes

It also helps to browse with a good VPN in place and never open anything that is not known to be good.

Also I NEVER use email links to open sites unless I am nearly 100% sure of the source. I browse directly there by typing an address or I do not use the site at all.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.