How do you validate that what you torrented is clean/no malware/spyware? Specifically, I torrented two things:

  • Astute Graphics Plug-ins Elite Bundle 3.9.1.7z from teamos. *It is 678MB so I can’t upload to Virustotal
  • Master Collection 2025 from uztracker (which is listed on monkrus’s website’s list of trackers). It is 37.5GB so I can’t upload to Virustotal.

I’m not sure what I should to do to be honest.

Edit: Would splitting the 37.5GB file into 650MB pieces and then scanning with virustotal help? Not sure if downloaded files need to be whole for it to work properly.

This is the results from virustotal (I could only scan 4 files in the master collection without running the iso)

Thank you.

  • dastanktal [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    It’s not like traditional antivirus software, it just includes a tool that you can use to manually scan files to see if it has a virus signature, which is all Eset and most virus scanners are doing on the backend. They’re also doing what’s called heuristics, which is where they’re using predictive modeling to try and identify if a program has what they call an attack signature. This does result in false positives, just so you’re aware.

    All virus total is doing is running a bunch of virus engines like eset and clamav on the back end to see if it triggers anything.

    If both your virus software and clamav comes back clean, then I’d trust it.

    • Yourname942@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      Would you trust it if the detection is 0, but there are network connections? (contacted domains and contacted IP addresses)

      • dastanktal [he/him]@hexbear.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        A lot of the time these apps will have heuristics that will reach back out and so you will see network connections occasionally.

        Without knowing more about this application, I don’t have the right context to evaluate whether or not I would trust something like that, so it’s gonna be up to your comfort level. But, if clamav came back clean and so did your other virus software, I would assume it’s not malicious traffic.