Resolve 18.0.1 - Windows Defender A/V Claims Infection

Get answers to your questions about color grading, editing and finishing with DaVinci Resolve.
  • Author
  • Message
Offline

lanstar

  • Posts: 4
  • Joined: Sat Aug 13, 2022 2:44 pm
  • Real Name: Timothy Pearson

Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSat Aug 13, 2022 2:55 pm

Hi all,

Just downloaded the 18.0.1 update to Resolve Studio. When unzipping the installer on a Windows 10 machine with Windows Defender Antivirus real-time scanning turned on, Windows Defender issues an alert that the installer is infected with something called a "ravadon.e" trojan.

I did not launch the installer after receiving this warning.

Since the Defender virus definition files change all the time, I wanted you to know this came from version 1.373.277.0 of Defender - updated on 8/13/2022 at 8:47AM Central Daylight Time in the USA.

Has anyone else seen this? Did some sort of malware actually creep into this release? How should Resolve Studio customers proceed?

Thanks!

Tim
Offline

lkupersmith

  • Posts: 5
  • Joined: Sat Dec 19, 2020 10:31 pm
  • Real Name: Lee Kupersmith

Windows Defender warns of virus in 18.0.1

PostSat Aug 13, 2022 9:07 pm

I wanted to update my Resolve Studio 17 to 18 today and while unzipping the download file, I get a warning from Defender about DaVinci_Resolve_Studio_18.0.1_Windows.exe being infected with Trojan:Win32/Ravadon.E

Malwarebytes (Free) doesn't see anything but I'm still hesitant to install. The file is too large to scan online with VirusTotal.

Just looking for assurances that this is a known false positive.
Offline
User avatar

Charles Bennett

  • Posts: 6283
  • Joined: Sat Nov 05, 2016 11:55 am
  • Location: United Kingdom

Re: Windows Defender warns of virus in 18.0.1

PostSun Aug 14, 2022 9:24 am

If you downloaded from the Blackmagic Support page then there is no problem. I use Windows Defender and get no such warning about Resolve.
Resolve Studio 19.0b1 build 20
Dell XPS 8700 i7-4790, 24GB RAM, 2 x Evo 860 SSDs, GTX1060/6GB (551.86 Studio Driver), Win10 Home (22H2), Speed Editor, Faderport mk1, Eizo ColorEdge CS230 + BenQ GW2270 + Samsung SA200, Canon C100mk2, Zoom H2n.
Offline

SkierEvans

  • Posts: 989
  • Joined: Wed Jan 24, 2018 9:59 pm
  • Location: Ottawa, Ontario
  • Real Name: Ron Evans

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 12:28 pm

I only have Defender on my PC editor and did not have this problem. How did you download the update? From the BM site or from within Resolve?
Threadripper 1920, Gigabyte X399 DESIGNARE EX, 32G RAM, Gigabyte 4070Ti 12G, ASUS PB328Q, IP4K, WIN10 Pro 22H2, Speed Editor

Resolve Studio 18, EDIUS 9WG,EDIUS X WG, Vegas 18

Studio Max M1 24 core GPU, 32G, 1T drive. iPad Pro 12.9` M2 16G, 1T
Offline
User avatar

Leslie Wand

  • Posts: 723
  • Joined: Wed Jul 24, 2013 5:56 am
  • Location: rural nsw, australia

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 12:45 pm

+1 skierevans.

where did you get the download from?
www.lesliewand.com.au
amd5 5800x / 32gb ram / rtx 3050 8gb / win 10 pro
sony ex3, sony a6400
Offline
User avatar

Leslie Wand

  • Posts: 723
  • Joined: Wed Jul 24, 2013 5:56 am
  • Location: rural nsw, australia

Re: Windows Defender warns of virus in 18.0.1

PostSun Aug 14, 2022 12:46 pm

+1 charles
www.lesliewand.com.au
amd5 5800x / 32gb ram / rtx 3050 8gb / win 10 pro
sony ex3, sony a6400
Offline

Jim Simon

  • Posts: 30295
  • Joined: Fri Dec 23, 2016 1:47 am

Re: Windows Defender warns of virus in 18.0.1

PostSun Aug 14, 2022 1:55 pm

Same as Charles for me.
My Biases:

You NEED training.
You NEED a desktop.
You NEED a calibrated (non-computer) display.
Offline

Jim Simon

  • Posts: 30295
  • Joined: Fri Dec 23, 2016 1:47 am

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 1:56 pm

That's not normal, Tim.
My Biases:

You NEED training.
You NEED a desktop.
You NEED a calibrated (non-computer) display.
Offline

lanstar

  • Posts: 4
  • Joined: Sat Aug 13, 2022 2:44 pm
  • Real Name: Timothy Pearson

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 2:33 pm

SkierEvans wrote:I only have Defender on my PC editor and did not have this problem. How did you download the update? From the BM site or from within Resolve?


Sorry, I should have included the source. The .zip came from clicking the "download" button on the update notice that comes up within Resolve when a new version is available. So it should have been the official Blackmagic .zip.

I think it's quite likely that this is a "false positive" - but was afraid to proceed with the install until I'd made an attempt to confirm.

There are thousands of Windows 10 machines with Defender out there running Resolve Studio... and of those thousands, some hundreds to thousands have likely downloaded this 18.0.1 update, of those who have downloaded the update, at least a good percentage of them will have up-to-date virus definition files installed for Defender. So if this is a real issue, several more people besides just me should be experiencing it.

I'll hold off another few days. If I don't hear any me-too's here in the forum about others with this issue, I'll feel a lot more confident.
Offline
User avatar

Charles Bennett

  • Posts: 6283
  • Joined: Sat Nov 05, 2016 11:55 am
  • Location: United Kingdom

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 3:42 pm

I, too, use only Defender and never see this warning. This is the only place where you should be downloading from, BMD's own Support page.
Attachments
Resolve Downloads.jpg
Resolve Downloads.jpg (270.81 KiB) Viewed 2793 times
Resolve Studio 19.0b1 build 20
Dell XPS 8700 i7-4790, 24GB RAM, 2 x Evo 860 SSDs, GTX1060/6GB (551.86 Studio Driver), Win10 Home (22H2), Speed Editor, Faderport mk1, Eizo ColorEdge CS230 + BenQ GW2270 + Samsung SA200, Canon C100mk2, Zoom H2n.
Offline

lkupersmith

  • Posts: 5
  • Joined: Sat Dec 19, 2020 10:31 pm
  • Real Name: Lee Kupersmith

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 4:16 pm

I got the exact virus warning, also from Windows Defender upon unzipping the downloaded file.

Originally, I downloaded via the popup in Resolve offering an update. Then after getting the warning, I downloaded again through the link on the BMD website. Same error.
I'm afraid to run the installation file until I can download a "clean" file.
Offline

lkupersmith

  • Posts: 5
  • Joined: Sat Dec 19, 2020 10:31 pm
  • Real Name: Lee Kupersmith

Re: Windows Defender warns of virus in 18.0.1

PostSun Aug 14, 2022 4:17 pm

I've moved my replies to a similar thread at viewforum.php?f=21
Offline

Nick2021

  • Posts: 760
  • Joined: Thu May 13, 2021 3:19 am
  • Real Name: Nick Zentena

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 5:32 pm

lanstar wrote:Hi all,

"ravadon.e" trojan.



If you google that all I see is various references to the Nvidia gaming drivers.
Offline
User avatar

Charles Bennett

  • Posts: 6283
  • Joined: Sat Nov 05, 2016 11:55 am
  • Location: United Kingdom

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostSun Aug 14, 2022 9:02 pm

You should try the Nvidia Studio driver. Also only download Nvidia drivers from nvidia.com. Not had any problems with Defender warnings doing this.
Resolve Studio 19.0b1 build 20
Dell XPS 8700 i7-4790, 24GB RAM, 2 x Evo 860 SSDs, GTX1060/6GB (551.86 Studio Driver), Win10 Home (22H2), Speed Editor, Faderport mk1, Eizo ColorEdge CS230 + BenQ GW2270 + Samsung SA200, Canon C100mk2, Zoom H2n.
Offline
User avatar

Charles Bennett

  • Posts: 6283
  • Joined: Sat Nov 05, 2016 11:55 am
  • Location: United Kingdom

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 10:15 am

You might need to consider if that trojan is already lurking on your computer and not actually part of the Resolve download.
Resolve Studio 19.0b1 build 20
Dell XPS 8700 i7-4790, 24GB RAM, 2 x Evo 860 SSDs, GTX1060/6GB (551.86 Studio Driver), Win10 Home (22H2), Speed Editor, Faderport mk1, Eizo ColorEdge CS230 + BenQ GW2270 + Samsung SA200, Canon C100mk2, Zoom H2n.
Offline

eli_singer

  • Posts: 43
  • Joined: Fri Nov 06, 2015 1:59 am

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 11:59 am

I too get this same warning, and also got the file via the update tool inside Resolve.
Any response from BMD on this? seems like a problem beyond 1 user according to this thread...

Eli
Offline

lanstar

  • Posts: 4
  • Joined: Sat Aug 13, 2022 2:44 pm
  • Real Name: Timothy Pearson

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 1:10 pm

I, too, would feel better were there some sort of input from BMD developers.

Some have commented about the infection we're all detecting being related to nVidia drivers on our machines. I would reiterate that the warning appears when doing nothing more than unzipping the Resolve installer.... the unzip utility is just reading the .zip, uncompressing the contents, and writing the uncompressed .exe installer. Defender is doing nothing more than watching what the unzip utility is writing to disk. It sees a pattern match and issues an alert.

It's also nearly certain that Resolve contains libraries of code copied in from from nVidia repositories to assist BMD programmers in accessing the GPU and other features of those graphics card models.... without having to code all the low-level stuff. So an nVidia related trojan could have crept in to the latest nVidia-provided developer library that BMD incorporated (quite innocently and with good intentions) into this release. Nothing to do with the nVidia drivers on the client machine(s).... Nothing intentional on anyone's part... but stuff like that happens sometimes.

Can anyone bump this anomaly "upstairs" to the developers and see what they say?

Thanks!

Tim
Offline
User avatar

Charles Bennett

  • Posts: 6283
  • Joined: Sat Nov 05, 2016 11:55 am
  • Location: United Kingdom

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 4:53 pm

What app did you use to extract (unzip) the files? I use the one built into Windows.
File extraction.jpg
File extraction.jpg (70.79 KiB) Viewed 2373 times

I have not had this problem with the 18.0.1 Studio version nor the download of the latest Studio driver from Nvidia.
The one thing I don't do is use the update notifications from BMD.

UPDATE
I have literally just done a test by downloading Studio 18.0.1 and unzipping it. No trojan detected by Defender. So as I said the trojan may already be on your computer. I would give it a scan if I were you.
Resolve Studio 19.0b1 build 20
Dell XPS 8700 i7-4790, 24GB RAM, 2 x Evo 860 SSDs, GTX1060/6GB (551.86 Studio Driver), Win10 Home (22H2), Speed Editor, Faderport mk1, Eizo ColorEdge CS230 + BenQ GW2270 + Samsung SA200, Canon C100mk2, Zoom H2n.
Offline

eli_singer

  • Posts: 43
  • Joined: Fri Nov 06, 2015 1:59 am

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 5:05 pm

This is happening to too many people to think they all hot Trojan horse anyway, especially since this is linked directly to an installation file from BMD.
So this needs to be addressed on another level.

Eli
Offline
User avatar

Charles Bennett

  • Posts: 6283
  • Joined: Sat Nov 05, 2016 11:55 am
  • Location: United Kingdom

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 5:14 pm

Well, I've just downloaded the free version of 18.0.1 and unzipped that. Still no trojan warning. So I cannot reproduce this problem with my system.
Resolve Studio 19.0b1 build 20
Dell XPS 8700 i7-4790, 24GB RAM, 2 x Evo 860 SSDs, GTX1060/6GB (551.86 Studio Driver), Win10 Home (22H2), Speed Editor, Faderport mk1, Eizo ColorEdge CS230 + BenQ GW2270 + Samsung SA200, Canon C100mk2, Zoom H2n.
Offline

lanstar

  • Posts: 4
  • Joined: Sat Aug 13, 2022 2:44 pm
  • Real Name: Timothy Pearson

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 6:21 pm

Charles Bennett wrote:What app did you use to extract (unzip) the files? I use the one built into Windows.


I use the same.

Charles Bennett wrote:I have not had this problem with the 18.0.1 Studio version nor the download of the latest Studio driver from Nvidia.


I've not had and issues/reports from the latest nVidia studio driver either. However, there's no telling what nVidia developer kit version might be embedded in Resolve. That's a different thing than the drivers and is dowloaded and used by folks who develop software to work with nVidia products.

Charles Bennett wrote:The one thing I don't do is use the update notifications from BMD.


I downloaded both and ran CRC checks on the exe's. The .zips dowwnloaded using each method have the same CRC - meaning they are bit-for-bit identical.

Charles Bennett wrote:UPDATE
I have literally just done a test by downloading Studio 18.0.1 and unzipping it. No trojan detected by Defender.


The Defender version that's giving the warning is v1.373.277.0 of Defender. Perhaps your version is different (newer or older)? I keep looking for new updates for Defender but haven't had Windows Update offer to download one yet. I'll keep trying that too.

Charles Bennett wrote:So as I said the trojan may already be on your computer. I would give it a scan if I were you.


I've done that and my system is clean. However, we already know the (potentially false positive) "infection" is in the Resolve installer .exe... that's because Defender reported the Davinci Resolve installer .exe that was being extracted as the infected file... I can make the warning from Defender appear over and over, just by attempting to re-extract this file from the .zip (where the virus signature is masked because the data in the .zip is compressed).

This is a real puzzler... there are some (perhaps only a few) who are having this issue and others (perhaps many) who can't reproduce the issue.. the version of Defender mentioned above (1.373.277.0) could likely be a critical requirement. I'll keep looking for both defender updates and for newer versions of the installer .zip (different CRC and/or time/date stamp) than the one I have now.

Thanks!

Tim
Offline

RCModelReviews

  • Posts: 1234
  • Joined: Wed Jun 06, 2018 1:39 am
  • Real Name: Bruce Simpson

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 6:36 pm

It is not unheard of for Windows Defender and other AV software to give false-flags. This usually happens because, simply by coincidence, there's a sequence of bytes in the code that just happens to match the fingerprint that the AV software is using to identify malware.

BMD should be onto this ASAP because until we've confirmed it is just a false-flag then you'll still be taking a risk if you want to put this code onto your system.
Resolve 18.1 Studio, Fusion 9 Studio
CPU: i7 8700, OS: Windows 10 32GB RAM, GPU: RTX3060
I'm refugee from Sony Vegas slicing video for my YouTube channels.
Offline

lkupersmith

  • Posts: 5
  • Joined: Sat Dec 19, 2020 10:31 pm
  • Real Name: Lee Kupersmith

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 7:17 pm

I'm running Defender v1.373.421.0 on Windows 10 with nVidia Studio Driver 511.65

If I unzip the download file using 7-Zip v22.01 I get the warning during the extraction.
If I unzip the file using Windows 10 Explorer, I do not get a warning.

If I scan the .exe after it is extracted using either 7-Zip or Explorer, I do not get a warning.

If I extract any other .zip file using 7-Zip, I do not get a warning, so I do not think it is a 7-Zip problem.
Offline

SkierEvans

  • Posts: 989
  • Joined: Wed Jan 24, 2018 9:59 pm
  • Location: Ottawa, Ontario
  • Real Name: Ron Evans

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 7:31 pm

My Threadripper is Win 10 Pro 21H2 with Defender 1.373.421.0 Second PC is 4790K with Win10 Home 21H2 same version numbers as Threadripper. I do not have 7 Zip installed on any PC so extraction was Windows. Download was with Chrome in both cases. Seems like 7 Zip is involved in some way.
Threadripper 1920, Gigabyte X399 DESIGNARE EX, 32G RAM, Gigabyte 4070Ti 12G, ASUS PB328Q, IP4K, WIN10 Pro 22H2, Speed Editor

Resolve Studio 18, EDIUS 9WG,EDIUS X WG, Vegas 18

Studio Max M1 24 core GPU, 32G, 1T drive. iPad Pro 12.9` M2 16G, 1T
Offline

Jim Simon

  • Posts: 30295
  • Joined: Fri Dec 23, 2016 1:47 am

Re: Resolve 18.0.1 - Windows Defender A/V Claims Infection

PostMon Aug 15, 2022 8:23 pm

SkierEvans wrote:Seems like 7 Zip is involved in some way.
That's what I use. Never had any warnings about Resolve.
My Biases:

You NEED training.
You NEED a desktop.
You NEED a calibrated (non-computer) display.

Return to DaVinci Resolve

Who is online

Users browsing this forum: Google [Bot], Igor Riđanović, panos_mts, thekaniack and 125 guests