# Julia.exe (portable 64 bit nightly and 1.6 rc) are infected?

**URL:** <https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757>\
**Category:** Performance\
**Created:** [February 22, 2021, 2:51am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757 "2021-02-22T02:51:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Humphrey\_Lee](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Humphrey\_Lee](https://discourse.julialang.org/u/Humphrey_Lee)\
**Post date:** [February 22, 2021, 2:51am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/1 "2021-02-22T02:51:17Z")

</div>

Tried couple downloads and running the julia.exe (1.6.0 rc and nightly - portable 64 bit versions) downloaded from [julialang.org](http://julialang.org). Each time, the Symantec on my system (Win10) caught it with SONAR.Dropper (Trojan?). Please check. Thanks.

![julia.exe_dropper](https://global.discourse-cdn.com/julialang/original/3X/0/9/096bedc64d11777d47b2e195699662d0d3432c76.png)

---

<div class="post-metadata">

**Author:** ![jling](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jling/32/212909_2.png) [@jling](https://discourse.julialang.org/u/jling)\
**Post date:** [February 22, 2021, 3:11am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/2 "2021-02-22T03:11:37Z")

</div>

does the checksum of the downloaded file match?

> **[VirusTotal](https://www.virustotal.com/gui/url/1b5a2721bae2f7c517aaf20a9646a3312c80c3e9b31ba0e2da9f8da8bdadf1d5/detection)**
>
> VirusTotal

nothing suspicious; also tried manual upload, still [all clear.](https://www.virustotal.com/gui/file/6b06cf83ebd1ddee8581cc7afa3803268497b73b300401aac82882210af9bfb8/detection)

---

<div class="post-metadata">

**Author:** ![Humphrey\_Lee](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Humphrey\_Lee](https://discourse.julialang.org/u/Humphrey_Lee)\
**Post date:** [February 22, 2021, 3:28am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/3 "2021-02-22T03:28:16Z")

</div>

The checksum don’t match.  
From official record…  
0789843a075ed1208f22f30903490c1f julia-1.6.0-rc1-win64.zip  
From my Win10 certutil …

```julia
certutil -hashfile julia-1.6.0-rc1-win64.zip
SHA1 hash of julia-1.6.0-rc1-win64.zip:
3f50117382942444695fe1c515a6976ca5fa3dee
CertUtil: -hashfile command completed successfully.

```

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [February 22, 2021, 3:33am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/4 "2021-02-22T03:33:26Z")

</div>

I can confirm these results for the portable Windows 64-bit Julia, 1.6 release candidate 1. But the Windows Defender found no threats at all.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [February 22, 2021, 3:39am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/5 "2021-02-22T03:39:33Z")

</div>

Actually, you forgot one argument, and it did not check MD5. Try it like this:

```julia
$ certutil -hashfile julia-1.6.0-rc1-win64.zip MD5
MD5 hash of julia-1.6.0-rc1-win64.zip:
0789843a075ed1208f22f30903490c1f
CertUtil: -hashfile command completed successfully.

```

---

<div class="post-metadata">

**Author:** ![Humphrey\_Lee](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Humphrey\_Lee](https://discourse.julialang.org/u/Humphrey_Lee)\
**Post date:** [February 22, 2021, 4:18am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/6 "2021-02-22T04:18:35Z")

</div>

Thanks @PetrKryslUCSD for the correction. Re-generated correct MD5.

```nohighlight
MD5 hash of julia-1.6.0-rc1-win64.zip:
0789843a075ed1208f22f30903490c1f
CertUtil: -hashfile command completed successfully.

```

Unpacked the zip, → run julia.exe, → error (Trojan) above appeared. Thanks @PetrKryslUCSD for confirming my observation. Observed this error for few weeks already.

---

<div class="post-metadata">

**Author:** ![jling](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jling/32/212909_2.png) [@jling](https://discourse.julialang.org/u/jling)\
**Post date:** [February 22, 2021, 4:19am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/7 "2021-02-22T04:19:38Z")

</div>

I think he didn’t confirm your observation…

> can confirm these results

was likely referring to your checksum which you both forgot the md5 flag.

I think in this case your anti-virus software is being dumb since virustotal reported nothing.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [February 22, 2021, 4:36am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/8 "2021-02-22T04:36:21Z")

</div>

But my AV did not detect any threat!

---

<div class="post-metadata">

**Author:** ![Humphrey\_Lee](https://avatars.discourse-cdn.com/v4/letter/h/a88e4f/32.png) [@Humphrey\_Lee](https://discourse.julialang.org/u/Humphrey_Lee)\
**Post date:** [February 22, 2021, 4:44am UTC](https://discourse.julialang.org/t/julia-exe-portable-64-bit-nightly-and-1-6-rc-are-infected/55757/9 "2021-02-22T04:44:10Z")

</div>

Tried Firefox and Edge to download on WIn10 → all suffer this problem. However, portable win32 has no problem. Then, downloaded (portable 64 bit) using my Android phone, transferred to my Win10. It ran without problem! My Win10 and Android are connect to same router. Seems like a user problem.
