Vanwege onderhoudswerkzaamheden die uw ervaring zouden moeten verbeteren, heeft deze website beperkte functionaliteit. Als een artikel uw probleem niet verhelpt en u een vraag wilt stellen, kan onze ondersteuningsgemeenschap u helpen in @FirefoxSupport op Twitter en /r/firefox op Reddit.

Zoeken in Support

Vermijd ondersteuningsscams. We zullen u nooit vragen een telefoonnummer te bellen, er een sms naar te sturen of persoonlijke gegevens te delen. Meld verdachte activiteit met de optie ‘Misbruik melden’.

Meer info

Deze conversatie is gearchiveerd. Stel een nieuwe vraag als u hulp nodig hebt.

Win.MxResIcn.Heur.Gen

  • 1 antwoord
  • 1 heeft dit probleem
  • 1 weergave
  • Laatste antwoord van James

more options

Hi. I'm using Linux Mint 20. I wanted to go back to Windows 10. Under Linux I downloaded the latest version of Firefox. I checked the installation file on the VirusTotal page. VirusTotal showed that the exe file contains the Win.MxResIcn.Heur.Gen trojan and the msi file contains Attention.APT-Bait.ContainShellCode! 1.9E28. Earlier installation files also contained some surprises. I don't think my Linux system contains any viruses. Installations of other browsers such as Opera or Chrome do not have these "add-ons". Interestingly, if I paste the link to the installation file into VirusTotal - there are no surprises. What is going on?

Hi. I'm using Linux Mint 20. I wanted to go back to Windows 10. Under Linux I downloaded the latest version of Firefox. I checked the installation file on the VirusTotal page. VirusTotal showed that the exe file contains the '''Win.MxResIcn.Heur.Gen''' trojan and the msi file contains '''Attention.APT-Bait.ContainShellCode! 1.9E28'''. Earlier installation files also contained some surprises. I don't think my Linux system contains any viruses. Installations of other browsers such as Opera or Chrome do not have these "add-ons". Interestingly, if I paste the link to the installation file into VirusTotal - there are no surprises. What is going on?
Gekoppelde schermafbeeldingen

Alle antwoorden (1)

more options

It is a false positive. If it was truly infected with something it would not have only one result but multiples. Cylance, Antiy-AVL, Clam and Norton has been among a short list that has given plenty of false positives at Virustotal and in AV client over the years with Firefox setups and especially the small stubs for windows.

I checked en-CA 78.0.2 win64 firefox .exe and MaxSecure was green though it was the only one red for en-US locale.

Other locales do not get this single false positive while the en-US may with MaxSecure on Virusetotal based on some research. It looks like it is having the usual issues with 7zS.sfx if you look on details page.

Firefox setups for Windows have been self-extracting 7z since Firefox 0.8 (Feb 2004). 7zS.sfx is the 7-ZIP self extractor stub from 7-ZIP that is used by Mozilla to pack the actual Firefox program with the 7-ZIP archive utility.

ex: https://www.reddit.com/r/privacytoolsIO/comments/gptqzf/windows10_firefox_malware_check/ https://www.reddit.com/r/firefox/comments/hni6cr/is_the_official_firefox_installer_infected_by/

ex: Bug#1468067 - Firefox installer doesn't pass VirusTotal test

Bewerkt door James op