WFX PCI detect contains (maybe) a trojaner

Discuss and announce Total Commander plugins, addons and other useful tools here, both their usage and their development.

Moderators: Hacker, petermad, Stefan2, white

Post Reply
Dali4u
Junior Member
Junior Member
Posts: 15
Joined: 2003-03-05, 14:37 UTC
Location: Passau

WFX PCI detect contains (maybe) a trojaner

Post by *Dali4u »

Hi,

i have installed this plugin:

http://www.totalcmd.net/plugring/wfx_pcidetect.html

After that i updated the plugin using the "update from internet"
that comes with this plugin.

Afterwards AVG AntiVirus reported a Trojaner and also TC quit itself with
a Virus warning.

Be carful with that plugin. I have uninstalled that plugin and everything
was fine, also TC doesn't quit itself anymore.
iana
Senior Member
Senior Member
Posts: 345
Joined: 2010-07-27, 22:00 UTC

Post by *iana »

When did U do an update?
The Authors site is down and I couldn't try to update the plugin (I think it only updates the database not the wfx), but he has written quite a few TC plugins and he uses a pe compressor to reduce the plugins size, I can't remember exactly but there was a page about his encryption plugin DarkCrypt being detected as a trojan by some AV scanners why not upload the wfx to virustotal.com, tc crashed because AVG didn't let it run, I use avast and gave wfx_pcidetect.wfx a scan it was clean (it was packed with upx tho)
maybe AVG reported it as a trojan because the plugin was loading a database in the background?
iana
Senior Member
Senior Member
Posts: 345
Joined: 2010-07-27, 22:00 UTC

Post by *iana »

just did an online update of the plugin and it's clean, even AVG 9.0.0.851 finds no problems, here's a link to virustotal
http://www.virustotal.com/file-scan/report.html?id=74d79c2b38da358c44a1b5c9420fb773ea16e1e04c4809d3f29006cf5c4f8b37-1284585994
User avatar
alexanderwdark
Senior Member
Senior Member
Posts: 270
Joined: 2008-04-14, 07:20 UTC
Location: Russia
Contact:

Re: WFX PCI detect contains (maybe) a trojaner

Post by *alexanderwdark »

This is simply false alarm of you anti-malware software (av). Please, send file to AV verdor support with "false alarm" title.

new site is here

Now there are only one false alarm on latest version of plugin
Post Reply