Q&A: About detection

SkyboundSteven

Level 6
Thread author
Verified
Jun 30, 2014
273
Q: I was downloading a file, then (antivirus) said "Win32.Malware-Gen" (in cases of Avast! Antivirus) or "Packed.Win32.(packer)"! Is this actually a virus?
A: On some cases, yes.
But some programs, like RDG Packer Detector, which is used to identify packers used in PE files (*.exe), may be packed and may return false positives.
In the case of "Trainers" downloaded from legitimate sites, it's 70% false alarm.
(BUT that doesn't mean you can trust all of them. Beware.)
But in most cases occurred with files downloaded with BitTorrent, you have to be careful.

Q: What exactly is Bitcoin Miner?
A: It uses infected computers to farm crypto-currency(a form of online currency) for unknown "masters" who are controlling the malware.
The computer may suffer from unstability, crash, slowing down, or even freezing as the malware uses up as much memory as possible to ramp up the farming speed.

Q: What is Fork Bomb?
A: Fork Bomb is a program which floods memory with clones of itself, or duplicating threads.
Think about this: The program creates two instances of itself, which makes two instances of itself, and so on.
It makes the computer unusable by filling up memory and consuming system resources as much as it can.

Q: I think my computer is so slow, and strange things are popping up on the screen! What could be the problem?
A: Your computer might be infected with malwares or viruses.
This usually happens when you run programs from untrusted source or you executed "installers".
In that case TwinHeadedEagle (at MalwareTips) can help you.
Give him the list of installed programs and he will make malicious things disappear for you.
Or, if you don't want to, manually find softwares that you DID NOT install from the uninstaller and remove them. (It's a good idea to send sample to Virus Exchange, but you don't have to)

Q: When opening a file, antivirus blocks the file. But when I scan it, it is clean! Am I going crazy, or is that file clean?
A: Don't trust it. Send the file to us (we, MalwareTips.) and wait for results.

Q: I see random popups and "Thank you installing our software" pages.
(NOTE: It's not a typo.)
A: Have you recently opened anything fishy? If you did something like I did, please look at the processes. If there's something really un-good, please send them to us (by finding the file in question).


<Revision 2 December 3, 2014>
All criticism and contributions are welcomed.
Moderators may edit the content of this post.
 
Last edited:

Behold Eck

Level 19
Verified
Top Poster
Well-known
Jun 22, 2014
906
I can remember Avira flagging torrent downloads as infected with trojans but lots of food for thought here.

Regards Eck:)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top