About TCMC...
Moderators: Hacker, petermad, Stefan2, white
- ghisler(Author)
- Site Admin
- Posts: 50532
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
They probably simply don't care, because no big programs use Upack. If they did this for UPX, many more programs (including Total Commander, which is used by many 100'000 people) would fail to work, which would directly affect the sales of these scanners...
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
Avast, AVG, Avira, Bitdefender...Yuta wrote:ViruScan still recognises it as virus. Generic.dx
Virus definitions 4.0.5502
Is there other similar tool?

HTH
Roman
Mal angenommen, du drückst Strg+F, wählst die FTP-Verbindung (mit gespeichertem Passwort), klickst aber nicht auf Verbinden, sondern fällst tot um.
- Samuel
- Power Member
- Posts: 1930
- Joined: 2003-08-29, 15:44 UTC
- Location: Germany, Brandenburg an der Havel
- Contact:
I wrote a macro program in Ahk:Yuta wrote:Is there other similar tool?
See here.
It can also handle ctrl+click on the Toolbar, but you can use it for pure macros too.
But only few people cared...

Hope it will help you.
25 false positives. I reported 17. Got problems with the following:
-Authentium (they don't like my email address)
-AVG (requires forum registration. TODO)
-eSafe (no online contact)
-eTrust-Vet (support temporarily unavailable. TODO)
-Ikarus (complicated support form in german, seems to require some special file, I don't get it)
-k7 (they thought I'm a spammer)
-PCTools (couldn't find contact information)
-Symantec (their contact software crashed)
Note to self:
MA245715211
-Authentium (they don't like my email address)
-AVG (requires forum registration. TODO)
-eSafe (no online contact)
-eTrust-Vet (support temporarily unavailable. TODO)
-Ikarus (complicated support form in german, seems to require some special file, I don't get it)
-k7 (they thought I'm a spammer)
-PCTools (couldn't find contact information)
-Symantec (their contact software crashed)
Note to self:
MA245715211
I think that the best way is to not use upack or all PE packer that do not have uncompress feature...m^2 wrote:25 false positives. I reported 17. Got problems with the following:
-Authentium (they don't like my email address)
-AVG (requires forum registration. TODO)
-eSafe (no online contact)
-eTrust-Vet (support temporarily unavailable. TODO)
-Ikarus (complicated support form in german, seems to require some special file, I don't get it)
-k7 (they thought I'm a spammer)
-PCTools (couldn't find contact information)
-Symantec (their contact software crashed)
Note to self:
MA245715211
I've done a small test.exe once packed with upack (on my virtual box machine), i download it to my PC and got virus warning ! (i've also done an un-winupacked version of TCMC and everything is fine for virus detection (exept that PE header is not clean)
I can understand your point, but you should also provide an unpacked version of your file (like ghisler do with unpacked TC).m^2 wrote:I won't give up Upack only because some idiots in AV companies think that only crapware makers use it.
For AV maker, upacked exe are very dificult to decompress so they give up and prefer give a false positive alert than ignoring a potential risk !
Impossible. About the time when I wrote TCMC I lost a hard drive. I have a backup of it's sources, but not the latest version.
Packed exes are very easy to decompress. They come with decompressor, don't they? It's enough to extract and use it.
And AFAIK Upack uses pure LZMA, there's a free, fast and well proven decompression library available for years.
Packed exes are very easy to decompress. They come with decompressor, don't they? It's enough to extract and use it.
And AFAIK Upack uses pure LZMA, there's a free, fast and well proven decompression library available for years.
I confirm that deupack 0.3 works and you can even repair the PE header with repairPE or XPElister... if M^2 authorize me, i can put tcmc.exe unpacked in a download area for a limited period of time...ZoSTeR wrote:You can unpack it with deupack 0.3 (link). I also tried the PE-Explorer plugin but it damaged the exe.
Upack doesn't have an official decompression method AFAIK.
Yesterday Sombra sent ma a set of 4 unpacked versions together with a summary of VirusTotal analysis.
Even the best ones show 4 positives.
I think it's best to distribute the whole package, I asked if it's OK for him.
In the meantime I'm discussing with AV crew about packed TCMC.
F-Secure, Sophos, TrendMicro reviewed the file already and said OK, but didn't update the definitions yet.
Prevx, McAffe - both want me to buy their products, but I think we'll solve the problem another way.
The other 12 companies didn't contact me yet.
Even the best ones show 4 positives.
I think it's best to distribute the whole package, I asked if it's OK for him.
In the meantime I'm discussing with AV crew about packed TCMC.
F-Secure, Sophos, TrendMicro reviewed the file already and said OK, but didn't update the definitions yet.
Prevx, McAffe - both want me to buy their products, but I think we'll solve the problem another way.
The other 12 companies didn't contact me yet.
I don't have a server, nsp, could you kindly upload it somewhere?
http://localhostr.com/files/392e3e/TCMC_u.7z
http://localhostr.com/files/392e3e/TCMC_u.7z
You can get tcmc_u.7Z on free download sharem^2 wrote:I don't have a server, nsp, could you kindly upload it somewhere?
....
2m^2you can contact me when you want me to remove the file !