View Issue Details

IDProjectCategoryView StatusLast Update
0004107Far Manager_Commonpublic2026-06-18 06:03
Reportermkaluza Assigned To 
PriorityhighSeverityblockReproducibilityalways
Status closedResolutionno change required 
Platformx64OSWindowsOS Version10
Product Version3.0 
Summary0004107: download installation - virus notice
DescriptionHi, I just wanted to download Far Manager. The browser blocked it because it contained a virus, I downloaded 6699 and also the nightly build 6700. When I bypassed the browser blocking, I uploaded the file to virus total. This is the result: https://www.virustotal.com/gui/file/af919953cc6fefd23053c84723e4a0bd974e2c8d7bf1a1120033ed5924fcc205

Does anyone have the same problem?
TagsNo tags attached.
Build0

Activities

mkaluza

2026-06-16 18:54

reporter  

2026-06-16 205213.png (115,381 bytes)   
2026-06-16 205213.png (115,381 bytes)   

DrKnS

2026-06-16 19:55

administrator   bugnote:0017708

Last edited: 2026-06-16 19:58

Antiviruses are, generally speaking, rubbish.
They will annoy you endlessly with false positives and then let the real threat in when you least expect it.

Read the Behavior page of your report, it's hilarious:

Checks for available system drives (often done to infect USB drives)
Of course we do. We show them in Disk menu, Alt+F1/F2.

Creates a process in a suspended state, likely for injection
Of course we create processes. Duh.
And yes, we create them in a suspended state to understand whether we need to wait for their termination.

Queries process token information to check for Administrator privileges or UAC elevation status
Yes, we do support elevated operations. Yes, we check first.

Queries the Volume Serial Number or Physical Hardware ID, possibly for anti-sandbox, victim profiling or environmental keying
Queries the volume information (name, serial number etc) of a device
Checks available memory
Checks the free space of harddrives
Yes, we show all this information in Info Panel, Ctrl+L.

Queried the FIPS cryptography policy, can be used to adapt C2 network encryption or by legitimate encryption software
Yes, we can encrypt and decrypt files, if that's what the user wants.

Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook
Queries the mount points and then resolves volume paths to enumerate storage devices
Yes, we show them in Disk menu and in Hotplug list.

And then "Crowdsourced Sigma Rules" complains about msiexec functionality, which is part of Windows. Facepalm.

These checks are by clowns and for clowns, what else to say.
Any product slightly more complex that "Hello World" will inevitably trigger some.

However, it's totally fine to have doubts and trust no one.
You can try github releases as an alternative: https://github.com/FarGroup/FarManager/releases
You can try 7z instead of msi.
You can compile the binaries from scratch if you want ultimate safety.
Or you can try contacting those vendors and asking them to update their exclusion databases or whatever.

Issue History

Date Modified Username Field Change
2026-06-16 18:54 mkaluza New Issue
2026-06-16 18:54 mkaluza File Added: 2026-06-16 205213.png
2026-06-16 19:55 DrKnS Note Added: 0017708
2026-06-16 19:56 DrKnS Note Edited: 0017708
2026-06-16 19:57 DrKnS Note Edited: 0017708
2026-06-16 19:58 DrKnS Note Edited: 0017708
2026-06-18 06:03 JohnDoe Status new => closed
2026-06-18 06:03 JohnDoe Resolution open => no change required
2026-06-18 06:03 JohnDoe Build => 0