How we check files

Every archive uploaded to the file section is sent automatically to VirusTotal, a service that runs the file through several dozen antivirus engines at once. The report is public: a link to it sits next to every download button, and it shows the verdict of every engine — including the ones whose opinion we do not count.

Below is how we read that report, and why a file with a couple of detections can still be listed here as safe.

1. Why we do not count detections

A file used to be blocked on any detection at all: one engine out of seventy objected and the Download button went dark. A simple rule, and a wrong one. Here is why.

Mods, trainers and translation packs are precisely the kind of file antivirus heuristics fire on most: packed executables, libraries that inject into another process, script loaders, self-extracting installers. By formal signs all of that looks like what malware does — and some engines react to the sign rather than to the behaviour.

How noisy this gets is easiest to show on real files from this site. Four archives that the old rule blocked, and who exactly flagged them:

— a Leon mod — 1 detection out of 68: MaxSecure, signature Trojan.Malware.300983.susgen;

— a Baldi's Basics mod — 1 out of 67: MaxSecure, the very same signature;

— a Plants vs. Zombies mod — 1 detection at the time it was blocked, and by the time we looked into the case the file had no detections left at all: 0 out of 68.

Not one of these files drew an objection from Microsoft Defender, Kaspersky, ESET or Bitdefender. In these cases "any detection blocks it" protected nobody — it simply removed perfectly ordinary files from the site.

2. Whose verdicts we count

Instead of counting detections we look at who raised the flag. A vote goes to vendors that run their own engine and are regularly certified by the independent labs (AV-Comparatives, AV-TEST, SE Labs), where false-positive rates are measured alongside detection rates.

First tier. A detection from any one of these is enough to block a file:

  • Microsoft Defender
  • Kaspersky
  • ESET NOD32
  • Bitdefender

Second tier. One vote each; two votes block the file:

  • Avast / AVG
  • Sophos
  • Trend Micro
  • McAfee / Trellix
  • Dr.Web
  • Fortinet
  • Malwarebytes
  • Symantec / Norton
  • Avira / F-Secure

Clones count as one vote. This detail matters: a number of engines on VirusTotal are the same engine under someone else's brand. The Bitdefender engine, for instance, ships inside GData, Emsisoft, Arcabit, MAX, VIPRE and eScan. Counted separately, one single opinion turns into six "independent" detections and a file gets blocked by one vendor's voice. So Avast and AVG are one vote here, McAfee and Trellix are one vote, and OEM builds of someone else's engine get no vote at all.

The reports show this in plain sight. In one archive we examined, the signature Gen:Variant.Lazy.733688 — word for word the same string — was returned by six "different" antivirus products: Bitdefender, ALYac, Arcabit, Emsisoft, GData and VIPRE. That is not six confirmations; it is one, printed six times.

Vendors absent from the lists above do not affect the decision. Their detections stay visible in the VirusTotal report — we hide nothing — but they do not switch off the download button.

3. The rule in full

A file is treated as unsafe and blocked if at least one of these holds:

— a first-tier engine marked it malicious;

— or at least two trusted vendors (across both tiers) marked it malicious or suspicious.

In every other case the file stays available.

The new rule is not softer than the old one — it is more accurate. That same archive with the repeated signature scored 15 detections out of 64, and among them were Bitdefender, Fortinet and Malwarebytes: a first-tier vendor plus two second-tier votes. It is blocked under the new rule as well, and by either condition on its own.

A lone suspicious verdict blocks nothing on its own. It is not a claim that the file contains malware; it is a heuristic saying "this behaves unusually" — and on packed installers and trainers that is the single most common thing anyone will ever say about a perfectly normal mod.

Microsoft Defender sits in the first tier for two reasons at once. It has one of the lowest measured false-positive rates, and it is also the antivirus most of our visitors are running: a file Defender considers malicious will not run on their machine anyway, whatever we may think of that verdict.

4. What happens to a blocked file

The download button goes dark, auto-install for that version becomes unavailable, and the author gets a private message listing the trusted vendors that flagged the file and the exact signature names. The file itself is not deleted: the author can re-upload the build or dispute the verdict.

If you are the author and you believe the detection is false, write to us through the feedback form. False positives happen to major vendors too, and they are taken seriously: every vendor listed above has a form for submitting a file for review.

5. What this check does not guarantee

No antivirus check offers a hundred per cent guarantee, and ours does not either. It means exactly what is written above: at the time of the scan, no antivirus we trust considered the file malicious.

Verdicts also change over time: databases get updated, and a detection that was there yesterday can be gone today — which is exactly what happened to the Plants vs. Zombies mod above. So the number in the VirusTotal report and our verdict can differ by scan date as well.

The VirusTotal report for every file is public — you can always look at it yourself and reach your own conclusion, including one that contradicts ours. We do recommend keeping your antivirus on and backing up your game files before installing anything: the most common way to break a game is not a virus but an incompatible file.