Relying on the relative download safety of www.Download.com, I downloaded a utility program (File Renamer Basic 4.0.3) at the following page:
http://www.download.com/File-Renamer-Basic/3000-2248_4-10703208.html
and installed it a few days ago. Avast did not alert on it at that time. Now Avast reports the downloaded file (filerenamerbasic.exe) to be a “Win32:Trojan-gen {VC}”. I also tried downloading the file from it’s creator, at:
http://www.sherrodcomputers.net/downloads/FileRenamerBasic.exe , but Avast also immediately alerted to this malware/trojan upon the download attempt.
I ran this file thru Jotti and VirusTotal, and they show only Avast and “TheHacker” A/V to identify this file as a trojan. None of the 30+ other A/V or malware detection programs appear to alert on this file.
PS: Although the program has high user ratings on Download.com, I discovered the following user review, buried a few pages back in the user reviews. Does this user info hold merit (?) or is the Avast alert on this file a false positive??
User Review: POTENTIALLY DANGEROUS INSTALLATION!
by: Deep Loner on 29-Jul-2007 12:44:04 PM
Cons: Use a program to monitor how the install program writes to the registry to see what I mean. File Renamer modifies the operating system to use its own custom versions of several .dll and .ocx system files, including Comdlg32.ocx, mscomctl.ocx, MSCOMCT2.ocx, Msvbvm60.dll, MSWINSCK.ocx, RICHTX32.ocx, vbscript.dll, and TABCTL32.ocx. At best, some programs will have compatibility problems or stop working, especially after File Renamer is uninstalled. At worst, no software that forces other programs to use its own versions of such critical system files can possibly be trusted to be safe.
Thanks in advance,
Acco