Topic: WIN10XPE virus  (Read 1948 times)

WIN10XPE virus
« on: May 27, 2018, 12:33:00 AM »

lvgandhi

  • Jr. Chef
  • **
  • Date Registered: Jul 2015
  • Posts: 71
Today when I was downloading Win10XPE_2018-05-17.7z, I got virus warning. Then I checked through Windows defender, I got warning as below in first file.  Details are given in second file.

Re: WIN10XPE virus
« Reply #1 on: May 27, 2018, 01:37:02 AM »

0scar

  • Code Baker
  • Chef
  • ***
  • Date Registered: Jan 2013
  • Posts: 309
Yes, Windows Defender now deletes pecmd.exe from target folder.

Re: WIN10XPE virus
« Reply #2 on: November 18, 2018, 03:56:21 PM »

max1185

  • Apprentice
  • *
  • Date Registered: Nov 2018
  • Posts: 1
Hello today I downloaded "Win10XPE_2018-10-12.7z".
The located file Win10XPE\Projects\Include\x86\AdditionalFiles\Windows\System32\Pecmd.exe is detected as Trojan by various anti-virus apps.
Please see virustotal.com/de/file/5932832013e7f839204f070f0e59f0761a980f95dd1612444558141a514af8f9/analysis/1542555225/

Is that a bad file (malware) or a good file?

Re: WIN10XPE virus
« Reply #3 on: November 18, 2018, 04:51:33 PM »

bob.omb

  • Code Baker
  • Grand Chef
  • *****
  • Location: USA
  • Date Registered: Jul 2017
  • Posts: 1261
it is not a virus, false positive.  a lot of unsigned / system changing / abused tools are used in PE, anti-virus would rather delete a good file then let you get infected, which is usually a good default choice unless your trying to actually use them to accomplish legit tasks.

A completely unrelated but good example of an abused tool is WirelessKeyView.exe by Nir Sofer (NirSoft - THIS IS NOT INCLUDED IN PE but IS included with Fab's AutoBackup).  This was originally created to "back up/retrieve" passwords for wireless networks.  WirelessKeyView.exe is an awesome tool that will save your butt when you are fixing a machine and have no way to get the original password, it is a life saver!  But because people abuse it in obvious ways, it has been flagged as a virus.  So when the real technician plugs in a USB with this tool, that was made with 100% good intention, into Windows 10, it gets immediately removed by Windows Defender. - Imagine being the guy who put in all the hard work to write the program actually trying to use it himself, then....poof! Windows Defender erases it  :lol:

It is always better to err on the side of caution but it is also very frustrating the way detections are made with AV software now. I have personally written simple tools from scratch that are flagged by AV...Super annoying.  :mad:
 
« Last Edit: November 18, 2018, 06:29:47 PM by bob.omb »

Re: WIN10XPE virus
« Reply #4 on: November 18, 2018, 07:27:12 PM »

James

  • Grand Chef
  • *****
  • Location: USA
  • Date Registered: Dec 2017
  • Posts: 2272
Quote
If using Windows 10 as your Host OS - you will need to allow a Windows Defender "Exception" for the Win10XPE folder ( I would suggest the same exception for any A/V software) in order to allow the program exe's to run without being blocked....

Reference -  http://theoven.org/index.php?topic=2569.0

 

Powered by EzPortal