PDA

View Full Version : How to properly report (possible) malware


Joe Forster/STA
09-01-2012, 05:45
Vague reports are getting frequent again, therefore below is an example of how a proper report with actual information should look like. Because unfounded, or downright fake, malware reports scare people off GameCopyWorld, we must take them seriously. Reports without specific information will be deleted on sight and their poster will first get an infraction, then a ban. You have been warned!

In Terminator: Future Shock v1.30 [US] No-CD Patch (http://www.gamecopyworld.com/games/pc_terminator.shtml#Terminator: Future Shock v1.30 [US] No-CD Patch), TFS130.COM contains malware "KillsYourPCInstantly.Win32.A" according to virus scanner "ScansViriiWell". See VirusTotal's report at: http://www.virustotal.com/file-scan/report.html?id=2e7a954c93194bc772e8cfc466ed9aa0ee3 bb911d1963c39e997cfc73fc8c291-1326112781.

The two most important details are the unambiguous definition (i.e. a link) of the download on GCW and the link to the results of an online virus scanner. Further notes:

To get a direct link to the download, go to http://www.gamecopyworld.com/games/pc_terminator.shtml and, from the Index, copy the Terminator: Future Shock v1.30 [US] No-CD Patch link onto the clipboard.
To put links containing square brackets into posts, use the [url="URL of the link"]name of the link[/url] syntax. (The quotation marks are required!)
To check files with multi-engine virus scanners, use VirusTotal (http://www.virustotal.com) and/or Jotti's malware scan (http://virusscan.jotti.org).


The example above is an old no-CD patch by me, there's no malware in it, and the malware/virus scanner names are fictional, too. ;)

TippeX
09-01-2012, 07:48
we could make an example using the EICAR string so people know what to see.. probably overkill though, but its a good idea to see how good (or bad) your particular av is and (if its decent) what its detected dialog should look like..without actually downloading a real virus etc

Joe Forster/STA
09-01-2012, 10:47
If people report malware then, implicitly, they also know how to recognize malware. The two online virus scanners are very easy to use, not much to comment on them. As for ranking anti virus software, we made our recommendation years ago: AVG, Kaspersky or NOD32, nothing else.

However, we could maintain somewhere a list of reported malware that is not malicious but is inherently part of some trainers, like Cheat Engine etc.