About TCMC...

Discuss and announce Total Commander plugins, addons and other useful tools here, both their usage and their development.

Moderators: white, Hacker, petermad, Stefan2

User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 48173
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Post by *ghisler(Author) »

They probably simply don't care, because no big programs use Upack. If they did this for UPX, many more programs (including Total Commander, which is used by many 100'000 people) would fail to work, which would directly affect the sales of these scanners...
Author of Total Commander
https://www.ghisler.com
User avatar
Yuta
Member
Member
Posts: 141
Joined: 2007-03-27, 16:52 UTC
Location: Argentina

Post by *Yuta »

ViruScan still recognises it as virus. Generic.dx
Virus definitions 4.0.5502

Is there other similar tool?
User avatar
m^2
Power Member
Power Member
Posts: 1413
Joined: 2006-07-12, 10:02 UTC
Location: Poland
Contact:

Post by *m^2 »

I don't know of any alternative.
I really can't work on the new version.:(
I'll contact virus companies then.

ADDED:
Well there is alternative. AHK. Search the forum and TC wiki, it is explained somewhere.
User avatar
Hacker
Moderator
Moderator
Posts: 13081
Joined: 2003-02-06, 14:56 UTC
Location: Bratislava, Slovakia

Post by *Hacker »

Yuta wrote:ViruScan still recognises it as virus. Generic.dx
Virus definitions 4.0.5502

Is there other similar tool?
Avast, AVG, Avira, Bitdefender... ;)

HTH
Roman
Mal angenommen, du drückst Strg+F, wählst die FTP-Verbindung (mit gespeichertem Passwort), klickst aber nicht auf Verbinden, sondern fällst tot um.
User avatar
Samuel
Power Member
Power Member
Posts: 1930
Joined: 2003-08-29, 15:44 UTC
Location: Germany, Brandenburg an der Havel
Contact:

Post by *Samuel »

Yuta wrote:Is there other similar tool?
I wrote a macro program in Ahk:
See here.

It can also handle ctrl+click on the Toolbar, but you can use it for pure macros too.

But only few people cared... :roll:
Hope it will help you.
User avatar
m^2
Power Member
Power Member
Posts: 1413
Joined: 2006-07-12, 10:02 UTC
Location: Poland
Contact:

Post by *m^2 »

25 false positives. I reported 17. Got problems with the following:
-Authentium (they don't like my email address)
-AVG (requires forum registration. TODO)
-eSafe (no online contact)
-eTrust-Vet (support temporarily unavailable. TODO)
-Ikarus (complicated support form in german, seems to require some special file, I don't get it)
-k7 (they thought I'm a spammer)
-PCTools (couldn't find contact information)
-Symantec (their contact software crashed)

Note to self:
MA245715211
User avatar
nsp
Power Member
Power Member
Posts: 1821
Joined: 2005-12-04, 08:39 UTC
Location: Lyon (FRANCE)
Contact:

Post by *nsp »

m^2 wrote:25 false positives. I reported 17. Got problems with the following:
-Authentium (they don't like my email address)
-AVG (requires forum registration. TODO)
-eSafe (no online contact)
-eTrust-Vet (support temporarily unavailable. TODO)
-Ikarus (complicated support form in german, seems to require some special file, I don't get it)
-k7 (they thought I'm a spammer)
-PCTools (couldn't find contact information)
-Symantec (their contact software crashed)

Note to self:
MA245715211
I think that the best way is to not use upack or all PE packer that do not have uncompress feature...

I've done a small test.exe once packed with upack (on my virtual box machine), i download it to my PC and got virus warning ! (i've also done an un-winupacked version of TCMC and everything is fine for virus detection (exept that PE header is not clean)
User avatar
m^2
Power Member
Power Member
Posts: 1413
Joined: 2006-07-12, 10:02 UTC
Location: Poland
Contact:

Post by *m^2 »

I won't give up Upack only because some idiots in AV companies think that only crapware makers use it.
User avatar
nsp
Power Member
Power Member
Posts: 1821
Joined: 2005-12-04, 08:39 UTC
Location: Lyon (FRANCE)
Contact:

Post by *nsp »

m^2 wrote:I won't give up Upack only because some idiots in AV companies think that only crapware makers use it.
I can understand your point, but you should also provide an unpacked version of your file (like ghisler do with unpacked TC).

For AV maker, upacked exe are very dificult to decompress so they give up and prefer give a false positive alert than ignoring a potential risk !
User avatar
m^2
Power Member
Power Member
Posts: 1413
Joined: 2006-07-12, 10:02 UTC
Location: Poland
Contact:

Post by *m^2 »

Impossible. About the time when I wrote TCMC I lost a hard drive. I have a backup of it's sources, but not the latest version.

Packed exes are very easy to decompress. They come with decompressor, don't they? It's enough to extract and use it.

And AFAIK Upack uses pure LZMA, there's a free, fast and well proven decompression library available for years.
User avatar
ZoSTeR
Power Member
Power Member
Posts: 1014
Joined: 2004-07-29, 11:00 UTC

Post by *ZoSTeR »

You can unpack it with deupack 0.3 (link). I also tried the PE-Explorer plugin but it damaged the exe.

Upack doesn't have an official decompression method AFAIK.
User avatar
nsp
Power Member
Power Member
Posts: 1821
Joined: 2005-12-04, 08:39 UTC
Location: Lyon (FRANCE)
Contact:

Post by *nsp »

ZoSTeR wrote:You can unpack it with deupack 0.3 (link). I also tried the PE-Explorer plugin but it damaged the exe.

Upack doesn't have an official decompression method AFAIK.
I confirm that deupack 0.3 works and you can even repair the PE header with repairPE or XPElister... if M^2 authorize me, i can put tcmc.exe unpacked in a download area for a limited period of time...
User avatar
m^2
Power Member
Power Member
Posts: 1413
Joined: 2006-07-12, 10:02 UTC
Location: Poland
Contact:

Post by *m^2 »

Yesterday Sombra sent ma a set of 4 unpacked versions together with a summary of VirusTotal analysis.
Even the best ones show 4 positives.
I think it's best to distribute the whole package, I asked if it's OK for him.

In the meantime I'm discussing with AV crew about packed TCMC.
F-Secure, Sophos, TrendMicro reviewed the file already and said OK, but didn't update the definitions yet.

Prevx, McAffe - both want me to buy their products, but I think we'll solve the problem another way.

The other 12 companies didn't contact me yet.
User avatar
m^2
Power Member
Power Member
Posts: 1413
Joined: 2006-07-12, 10:02 UTC
Location: Poland
Contact:

Post by *m^2 »

I don't have a server, nsp, could you kindly upload it somewhere?

http://localhostr.com/files/392e3e/TCMC_u.7z
User avatar
nsp
Power Member
Power Member
Posts: 1821
Joined: 2005-12-04, 08:39 UTC
Location: Lyon (FRANCE)
Contact:

Post by *nsp »

m^2 wrote:I don't have a server, nsp, could you kindly upload it somewhere?
....
You can get tcmc_u.7Z on free download share

2m^2you can contact me when you want me to remove the file !
Post Reply