Win.MxResIcn.Heur.Gen

Maybe the file got infected after you downloaded it?

I submitted the file I had downloaded to Jotti:

And provided the download URL (https://github.com/darktable-org/darktable/releases/download/release-4.8.0/darktable-4.8.0-win64.exe) to VirusTotal:

I then re-downloaded the file and submitted it to VT directly (it seems it does not scan URLs as I thought it would), I got 1 warning from dozens of tools.

That warning is not an actual detection, it’s some ML (machine-learning, read: “AI”) guess. See: c# - Virustotal Trapmine suspicious.low.ml.score - Stack Overflow

I down loaded the file on 2 different computers, work, and home and have the same issue on both.

I just downloaded again from the github site above, ran through Virus Total and again comes up with suspicious malware highlight on red. An if I try to install Defender blocks it again.

I cannot reproduce what you see, sorry. Maybe your computer already has some malware, and downloaded files, as they are written to disk, get infected?

Right now, all I know is when I try to install, Windows Defender will not let me install. I am downloading from the same site on 2 different computers and having the same issue. If I run this file through Jotti or Virus Total as suggested, I still get that the file has an issue.

If in doubt, you can self compile.

Right. I also tested on 2 computers (a Windows laptop, a Linux PC), checked both the version I downloaded a week ago, and one I downloaded today (the two were identical), and got no reports.

Maybe get a bootable pendrive (that’s known to be clean, maybe ask a friend to create it for you), boot from that, and scan your PC. I cannot do more to investigate this: there were only the two heuristic ‘AI’ / ‘ML’ positives.

Can you download the exe in the browser on your phone, and then upload it to the online checkers?

I got the same as under Windows and Linux: 2 heuristic warnings on VirusTotal:

Jotti: I forced a new scan. Still clean. Could you compare the SHA1 hash reported by the scanner with what’s reported for you?

https://virusscan.jotti.org/en-GB/filescanjob/4vuunzue2y

Jotti reported the hashes:
MD5: 41b461a70df4734bfe293cdc44bd5578
SHA1: b6f9fe4140caeb03b8d3580be26dccf0245bc5df

If you get different hash values, then your file is different!

I’ve moved a bunch of posts here from the release post of dt 4.8 as we were having two of the same discussions in parallel.

1 Like

Neither Jotti or Virus Total will allow me to chose the file to scan

| kofa István Kovács Supporter
June 28 |

  • | - |

Can you download the exe in the browser on your phone, and then upload it to the online checkers?

I got the same as under Windows and Linux: 2 heuristic warnings on VirusTotal:

virustotal.com

VirusTotal

VirusTotal

Jotti: I forced a new scan. Still clean. Could you compare the SHA1 hash reported by the scanner with what’s reported for you?

https://virusscan.jotti.org/en-GB/filescanjob/4vuunzue2y

Jotti reported the hashes:
MD5: 41b461a70df4734bfe293cdc44bd5578
SHA1: b6f9fe4140caeb03b8d3580be26dccf0245b

If you get different hash values, then your file is different!

I did say that neither virus scan would allow me to chose the file, but I did download 4.8.0 to my phone.

we post the sha256 on the release post:

sha256sum darktable-4.8.0-win64.exe
a1396ca8640df4b25ae41ef0dec1649e2c9f33018e955090e770737abf9d2160

did you check the checksums of the downloaded package? If that matches the given checksum in the darktable release page (Release release 4.8.0 · darktable-org/darktable · GitHub), then the package is ok and you might ask your virus software provider to correct their detection :wink:

I’m giving up, I cannot follow this. I thought you said you’d scanned it with Jotti:

Can’t you just choose to ignore it if you are confident to do so…also there are several other recent threads on this that you can also review for feedback. I self compile to an exe package and install and it doesn’t trigger any warnings… so that could be a way to go if you are cautiously viewing this

When you uploaded it from your PC, Jotti created a link (just like the one posted above). Can you share that link? The screen then shows the SHA1 and MD5 hashes (unfortunately not the SHA256 that’s provided on the darktable site).

The file I downloaded from the darktable site has the following hashes:

The MD5 sum – it matches the one Jotti reported in https://discuss.pixls.us/t/win-mxresicn-heur-gen/44036/27:

kofa@eagle:/tmp$ md5sum darktable-4.8.0-win64.exe 
41b461a70df4734bfe293cdc44bd5578  darktable-4.8.0-win64.exe

The SHA1 sum – it also matches the one reported by Jotti:

kofa@eagle:/tmp$ sha1sum darktable-4.8.0-win64.exe 
b6f9fe4140caeb03b8d3580be26dccf0245bc5df  darktable-4.8.0-win64.exe

The SHA256 sum – it is the same value as Mica reported (Win.MxResIcn.Heur.Gen - #31 by paperdigits), quoted from the release notes (Release release 4.8.0 · darktable-org/darktable · GitHub):

kofa@eagle:/tmp$ sha256sum darktable-4.8.0-win64.exe 
a1396ca8640df4b25ae41ef0dec1649e2c9f33018e955090e770737abf9d2160  darktable-4.8.0-win64.exe

This means Jotti really scanned the file that is published on the darktable site, and it reported absolutely no findings.
The virustotal scan report for that file (you can search by the SHA256 hash) is here (the long code at the end of the URL is the hash), and it only has the two ML/AI heuristic warnings, no actual scanner found any known pattern.

BTW, Jotti is also searchable by hash:
https://virusscan.jotti.org/en-GB/search/hash
The particular installer file, using the hash:
https://virusscan.jotti.org/en-GB/search/hash/a1396ca8640df4b25ae41ef0dec1649e2c9f33018e955090e770737abf9d2160

Until you provide the hashes / screenshots, there’s really nothing more to add.

Here is the link darktable-4.8.0-win64.exe - Jotti's malware scan

Now none of the scanners show an issue but defender still does

I installed darktable 4.8.0 on Windows 11 when it came out. There was a warning, like for all software that is downloaded from the internet. There is nothing to fix there. Only you can decide if you trust the developers and the community, or you don’t.

The following may be related:

If the dt installer was Microsoftverified, would the false positive issue disappear?