[TC11.55RC6] Virus warning
Moderators: Hacker, petermad, Stefan2, white
[TC11.55RC6] Virus warning
[TC11.55RC6] The CAB file inside the setup file is trigger a virus warning. If I extract the RAR file with WinRAR, it works normally, but when I open it with Total Commander, I get a virus alert. (Windows10 Virus & Threat protection)
- ghisler(Author)
- Site Admin
- Posts: 50824
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: [TC11.55RC6] Virus warning
Not confirmed. Virustotal also finds nothing:
64-bit: https://www.virustotal.com/gui/file/9b59355b900e8a1cd4943979d5dd072d752e4bc3cd1ba4498530ac9e457266c8
32-bit: https://www.virustotal.com/gui/file/ae70ef4254eb3f7a7c4863ff25fef4839ebebb9ddd36aee259b22626819006b6
Combined: https://www.virustotal.com/gui/file/8f08df88c27db92943e7b6804a60acbef730c45b7c5027bf74c700e94e64b8b8
What virus is being reported?
64-bit: https://www.virustotal.com/gui/file/9b59355b900e8a1cd4943979d5dd072d752e4bc3cd1ba4498530ac9e457266c8
32-bit: https://www.virustotal.com/gui/file/ae70ef4254eb3f7a7c4863ff25fef4839ebebb9ddd36aee259b22626819006b6
Combined: https://www.virustotal.com/gui/file/8f08df88c27db92943e7b6804a60acbef730c45b7c5027bf74c700e94e64b8b8
What virus is being reported?
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
Re: [TC11.55RC6] Virus warning
Not confirmed.
The actual Windows Defender scans the whole setup with no viruses
and also opening the archive in TC shows no problems.
VirusTotal says
No security vendors flagged this file as malicious.
I guess your antivirus database is not actual.
The actual Windows Defender scans the whole setup with no viruses
and also opening the archive in TC shows no problems.
VirusTotal says
No security vendors flagged this file as malicious.
I guess your antivirus database is not actual.
Windows 11 Home, Version 24H2 (OS Build 26100.4351)
TC 11.55 RC6 x64 / x86
Everything 1.5.0.1395a (x64), Everything Toolbar 1.5.5.0, Listary Pro 6.3.2.88
QAP 11.9.0.3 x64
TC 11.55 RC6 x64 / x86
Everything 1.5.0.1395a (x64), Everything Toolbar 1.5.5.0, Listary Pro 6.3.2.88
QAP 11.9.0.3 x64
Re: [TC11.55RC6] Virus warning
2Gokhan
Do you mean the CAB file?If I extract the RAR file with WinRAR
License #524 (1994)
Danish Total Commander Translator
TC 11.55rc4 32+64bit on Win XP 32bit & Win 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1393a
TC 3.60b4 on Android 6, 13, 14
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
Danish Total Commander Translator
TC 11.55rc4 32+64bit on Win XP 32bit & Win 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1393a
TC 3.60b4 on Android 6, 13, 14
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
Re: [TC11.55RC6] Virus warning
I restarted my computer and extracted the sample.rar file using WinRAR. There was no issue. Then, I tried with TC11.51, and again, I got a warning that the sample.rar file was infected with a virus, and Windows10 Virus & Threat Protection deleted it again.
Meanwhile, the "2025-06 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5060533)" had downloaded in the background.
Now, I no longer get a warning when opening the RAR file.
However, when I try to access the CAB file inside the setup file "tc1155x64_rc6.exe" using Total Commander, I still get the following warning message:
-------------
Sample submission
Windows Defender Antivirus would like to check the following file to see if they are safe
-> C:\User\abc\AppData\Local\Temp\_tc\INSTALL.CAB
-------------
I had never received this warning with any previous versions.
Meanwhile, the "2025-06 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5060533)" had downloaded in the background.
Now, I no longer get a warning when opening the RAR file.
However, when I try to access the CAB file inside the setup file "tc1155x64_rc6.exe" using Total Commander, I still get the following warning message:
-------------
Sample submission
Windows Defender Antivirus would like to check the following file to see if they are safe
-> C:\User\abc\AppData\Local\Temp\_tc\INSTALL.CAB
-------------
I had never received this warning with any previous versions.
Re: [TC11.55RC6] Virus warning
Where is the connection between this sample.rar file and TC's install.cab (or tc1155x64_rc6.exe)? What does the sample.rar file contain?
#101164 Personal licence
Ryzen 5 2600, 16 GiB RAM, ASUS Prime X370-A, Win7 x64
Plugins: Services2, Startups, CertificateInfo, SignatureInfo, LineBreakInfo - Download-Mirror
Ryzen 5 2600, 16 GiB RAM, ASUS Prime X370-A, Win7 x64
Plugins: Services2, Startups, CertificateInfo, SignatureInfo, LineBreakInfo - Download-Mirror
Re: [TC11.55RC6] Virus warning
I previously worked with the 'sample.rar' file using older versions of Total Commander and never received any warnings. However, after getting the warning about the CAB file inside 'tc1155x64_rc6.exe,' I also started receiving consecutive warnings about 'sample.rar'.
The warning about submitting a sample is not triggered by 'tc1155x64_rc6.exe' itself, but rather by the CAB file inside it.
Windows Defender is no longer flagging sample.rar as a threat.
sample.rar contain docx files
The warning about submitting a sample is not triggered by 'tc1155x64_rc6.exe' itself, but rather by the CAB file inside it.
Windows Defender is no longer flagging sample.rar as a threat.
sample.rar contain docx files
Re: [TC11.55RC6] Virus warning
Turn off the worse than useless Windows Defender: problem solved
Re: [TC11.55RC6] Virus warning
No, I have no such problem with Defender.DRP535 wrote: 2025-06-14, 09:12 UTC Turn off the worse than useless Windows Defender: problem solved
I was Ant+virus admin in large companies with all sort of solutions.
At home, I have Defender since a long time and there are fewer problems compared to 3rd party solutions.
Windows 11 Home, Version 24H2 (OS Build 26100.4351)
TC 11.55 RC6 x64 / x86
Everything 1.5.0.1395a (x64), Everything Toolbar 1.5.5.0, Listary Pro 6.3.2.88
QAP 11.9.0.3 x64
TC 11.55 RC6 x64 / x86
Everything 1.5.0.1395a (x64), Everything Toolbar 1.5.5.0, Listary Pro 6.3.2.88
QAP 11.9.0.3 x64
- ghisler(Author)
- Site Admin
- Posts: 50824
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: [TC11.55RC6] Virus warning
What you see in action is a so-called behavior based analysis: The scanner sees that an installation file (cab) gets unpacked to TEMP, and since it was taught that some virus downloaders do this, it flagged the process as suspicious. You will probably not get the error when you instead unpack the CAB file with F5 to some other directory. I do not currently get this warning with Windows Defender, so maybe they fixed it in the meantime.
Btw, a long time ago I changed the behavior of my installer for exactly this reason: Previously, the installer would unpack the CAB file and actual install.exe to TEMP, and then run install.exe from TEMP for the installation. This caused too many problems with virus scanners, so now the installer directly installs the files from itself without putting anything in TEMP. This is done by packing the CAB file with 0 compression so it can be accessed directly. Unfortunately there is no such workaround when opening inner archives, because most inner archives (e.g. tar.gz) are not just stored.
Since this isn't a Total Commander bug I could fix, I'm moving this thread to the English forum.
Btw, a long time ago I changed the behavior of my installer for exactly this reason: Previously, the installer would unpack the CAB file and actual install.exe to TEMP, and then run install.exe from TEMP for the installation. This caused too many problems with virus scanners, so now the installer directly installs the files from itself without putting anything in TEMP. This is done by packing the CAB file with 0 compression so it can be accessed directly. Unfortunately there is no such workaround when opening inner archives, because most inner archives (e.g. tar.gz) are not just stored.
Since this isn't a Total Commander bug I could fix, I'm moving this thread to the English forum.
Moderator message from: ghisler(Author) » 2025-06-15, 07:47 UTC
Moved to English forum
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com