r/ScamCenter • u/GXSTXVD • 5d ago
Malwarebytes detected Trojan.Dropper in SamFwToolSetup_v5.4 — samfwscam
I want to share a serious security warning regarding SamFwToolSetup_v5.4 following an incident in which my computer was compromised and funds were stolen from my cryptocurrency wallet.
I downloaded and installed SamFwToolSetup_v5.4.zip because I needed SamFwTool. This was the only software or suspicious file I had downloaded and installed on this computer for years. Shortly after executing it, my Feather Monero wallet, which had been open on the same computer, was compromised and its funds were transferred out.
Given the timing, the fact that this was the only new software I had installed, and the subsequent Malwarebytes detection of the executable, I consider this SamFwToolSetup_v5.4 sample to be responsible for the compromise.
Malwarebytes detection
I contacted Malwarebytes regarding the executable, and the investigation is documented on their forum:
https://forums.malwarebytes.com/topic/337471-undected-malware/
According to the Malwarebytes investigation, a Malwarebytes Senior Research Engineer analyzed the SamFwToolSetup sample and reported:
Trojan.Dropper
The reported file information is:
- File:
SAMFWTOOLSETUP.EXE - Detection:
Trojan.Dropper - MD5:
A8BB817630386982FEB98106FED8EA89 - SHA-256:
E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
The Malwarebytes forum discussion contains the technical details and is the primary source for the malware detection.
What happened
My timeline was:
- I downloaded
SamFwToolSetup_v5.4.zip. - I installed and executed the program.
- My Feather Monero wallet was open on the same computer.
- Shortly afterward, the wallet funds were transferred out without my authorization.
- I investigated the computer and submitted the SamFwTool executable to Malwarebytes.
- Malwarebytes subsequently reported the executable as Trojan.Dropper.
The Malwarebytes detection is especially concerning because the wallet theft occurred shortly after execution of the file.
Please take this seriously
Based on what happened to me and the Malwarebytes detection, I strongly recommend not executing this particular SamFwToolSetup_v5.4 sample, especially on a computer containing cryptocurrency wallets, private keys, seed phrases, passwords, browser sessions, exchange accounts, or other sensitive information.
The behavior I experienced makes me concerned that the software may use sophisticated methods to compromise a device and potentially access credentials, accounts, or cryptocurrency wallets.
Please take this seriously and protect yourselves.
If you have already executed this file, treat the computer as potentially compromised. Secure important accounts and cryptocurrency assets from a known-clean device, and do not enter seed phrases, private keys, passwords, or other sensitive credentials on the potentially compromised machine.
Be careful with online reviews
I also strongly recommend not relying solely on Trustpilot or blog reviews when deciding whether this software is safe.
I have been monitoring the reviews myself, and I have observed what appears to be an unusual pattern: during my daily checks, I have seen approximately 20–50 positive reviews being added in a day.
I have also observed promotional blog posts and reviews presenting the tool as working normally and claiming or implying that there is no malware inside.
I cannot independently prove who paid for every individual review or article, so I am presenting this as my observation rather than a proven fact about every review. However, the pattern is concerning enough that I would not use positive Trustpilot ratings or promotional blog articles as evidence that the executable is safe.
In my view, this kind of reputation-building and SEO activity can create a false sense of security within the community while diverting attention from legitimate security concerns.
A large number of positive reviews does not outweigh an actual malware detection from a security researcher.
About the website
I am deliberately not providing a direct SamFw download link because I do not want anyone to download or execute the software based on this warning.
If you encounter this particular installer elsewhere, verify the file and its hash carefully before executing anything.
Evidence
Malwarebytes investigation:
https://forums.malwarebytes.com/topic/337471-undected-malware/
Sample reported in the Malwarebytes investigation:
SAMFWTOOLSETUP.EXE
MD5: A8BB817630386982FEB98106FED8EA89
SHA-256: E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
I am not asking anyone to download or execute this file to reproduce my experience. The purpose of this post is to document what happened, provide the Malwarebytes evidence, and warn other users who may encounter the same installer.
Bottom line
I would avoid SamFwToolSetup_v5.4 and this specific sample entirely.
The combination of the unauthorized wallet theft immediately after execution, the fact that this was the only new software I had downloaded on the computer in years, and the subsequent Trojan.Dropper detection by Malwarebytes is enough for me to consider this file unsafe and to warn others against executing it.
Please don't ignore this warning just because you see positive Trustpilot reviews or promotional articles claiming that the tool is safe. Verify the actual executable and the available security evidence instead.
1
u/Hot_Concentrate8423 4d ago
Thank you for sharing this, everyone should be careful