[TC11.55RC6] Virus warning

English support forum

Moderators: Hacker, petermad, Stefan2, white

Post Reply
Gokhan
Junior Member
Junior Member
Posts: 9
Joined: 2012-01-10, 14:23 UTC

[TC11.55RC6] Virus warning

Post by *Gokhan »

[TC11.55RC6] The CAB file inside the setup file is trigger a virus warning. If I extract the RAR file with WinRAR, it works normally, but when I open it with Total Commander, I get a virus alert. (Windows10 Virus & Threat protection)
User avatar
Horst.Epp
Power Member
Power Member
Posts: 7009
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Re: [TC11.55RC6] Virus warning

Post by *Horst.Epp »

Not confirmed.
The actual Windows Defender scans the whole setup with no viruses
and also opening the archive in TC shows no problems.
VirusTotal says
No security vendors flagged this file as malicious.

I guess your antivirus database is not actual.
Windows 11 Home, Version 24H2 (OS Build 26100.4351)
TC 11.55 RC6 x64 / x86
Everything 1.5.0.1395a (x64), Everything Toolbar 1.5.5.0, Listary Pro 6.3.2.88
QAP 11.9.0.3 x64
User avatar
petermad
Power Member
Power Member
Posts: 16099
Joined: 2003-02-05, 20:24 UTC
Location: Denmark
Contact:

Re: [TC11.55RC6] Virus warning

Post by *petermad »

2Gokhan
If I extract the RAR file with WinRAR
Do you mean the CAB file?
License #524 (1994)
Danish Total Commander Translator
TC 11.55rc4 32+64bit on Win XP 32bit & Win 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1393a
TC 3.60b4 on Android 6, 13, 14
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
Gokhan
Junior Member
Junior Member
Posts: 9
Joined: 2012-01-10, 14:23 UTC

Re: [TC11.55RC6] Virus warning

Post by *Gokhan »

I restarted my computer and extracted the sample.rar file using WinRAR. There was no issue. Then, I tried with TC11.51, and again, I got a warning that the sample.rar file was infected with a virus, and Windows10 Virus & Threat Protection deleted it again.

Meanwhile, the "2025-06 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5060533)" had downloaded in the background.

Now, I no longer get a warning when opening the RAR file.

However, when I try to access the CAB file inside the setup file "tc1155x64_rc6.exe" using Total Commander, I still get the following warning message:
-------------
Sample submission
Windows Defender Antivirus would like to check the following file to see if they are safe
-> C:\User\abc\AppData\Local\Temp\_tc\INSTALL.CAB
-------------
I had never received this warning with any previous versions.
User avatar
Dalai
Power Member
Power Member
Posts: 10016
Joined: 2005-01-28, 22:17 UTC
Location: Meiningen (Südthüringen)

Re: [TC11.55RC6] Virus warning

Post by *Dalai »

Where is the connection between this sample.rar file and TC's install.cab (or tc1155x64_rc6.exe)? What does the sample.rar file contain?
#101164 Personal licence
Ryzen 5 2600, 16 GiB RAM, ASUS Prime X370-A, Win7 x64

Plugins: Services2, Startups, CertificateInfo, SignatureInfo, LineBreakInfo - Download-Mirror
Gokhan
Junior Member
Junior Member
Posts: 9
Joined: 2012-01-10, 14:23 UTC

Re: [TC11.55RC6] Virus warning

Post by *Gokhan »

I previously worked with the 'sample.rar' file using older versions of Total Commander and never received any warnings. However, after getting the warning about the CAB file inside 'tc1155x64_rc6.exe,' I also started receiving consecutive warnings about 'sample.rar'.

The warning about submitting a sample is not triggered by 'tc1155x64_rc6.exe' itself, but rather by the CAB file inside it.

Windows Defender is no longer flagging sample.rar as a threat.

sample.rar contain docx files
User avatar
DRP535
Senior Member
Senior Member
Posts: 307
Joined: 2003-03-03, 11:25 UTC

Re: [TC11.55RC6] Virus warning

Post by *DRP535 »

Turn off the worse than useless Windows Defender: problem solved
User avatar
Horst.Epp
Power Member
Power Member
Posts: 7009
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Re: [TC11.55RC6] Virus warning

Post by *Horst.Epp »

DRP535 wrote: 2025-06-14, 09:12 UTC Turn off the worse than useless Windows Defender: problem solved
No, I have no such problem with Defender.
I was Ant+virus admin in large companies with all sort of solutions.
At home, I have Defender since a long time and there are fewer problems compared to 3rd party solutions.
Windows 11 Home, Version 24H2 (OS Build 26100.4351)
TC 11.55 RC6 x64 / x86
Everything 1.5.0.1395a (x64), Everything Toolbar 1.5.5.0, Listary Pro 6.3.2.88
QAP 11.9.0.3 x64
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 50824
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: [TC11.55RC6] Virus warning

Post by *ghisler(Author) »

What you see in action is a so-called behavior based analysis: The scanner sees that an installation file (cab) gets unpacked to TEMP, and since it was taught that some virus downloaders do this, it flagged the process as suspicious. You will probably not get the error when you instead unpack the CAB file with F5 to some other directory. I do not currently get this warning with Windows Defender, so maybe they fixed it in the meantime.

Btw, a long time ago I changed the behavior of my installer for exactly this reason: Previously, the installer would unpack the CAB file and actual install.exe to TEMP, and then run install.exe from TEMP for the installation. This caused too many problems with virus scanners, so now the installer directly installs the files from itself without putting anything in TEMP. This is done by packing the CAB file with 0 compression so it can be accessed directly. Unfortunately there is no such workaround when opening inner archives, because most inner archives (e.g. tar.gz) are not just stored.

Since this isn't a Total Commander bug I could fix, I'm moving this thread to the English forum.

Moderator message from: ghisler(Author) » 2025-06-15, 07:47 UTC

Moved to English forum
Author of Total Commander
https://www.ghisler.com
Post Reply