• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

VirusTotal: 40+ AV Engine Scanner (Online, Free)

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

Jmtyra

Member
Joined
Aug 18, 2010
Location
Dallas/Fort-Worth
I'm sure many of you have used or come across this before, but we were chatting in another thread about malware/virii removal, and it reminded me of this tool.

Any-who, BOOKMARK THIS! virustotal.com :thup:

You upload a file in question, and it'll run it through 40+ AV engines. I think it also takes email submissions, if you want. It'll also give you a direct link for the results, to share with others or whatever.

Here is the list of AV engines it runs through. Pretty flippin' cool IMHO. :D

Enjoy!

Credits

VirusTotal is a service developed by Hispasec Sistemas, an independent IT Security laboratory, that uses several command line versions of antivirus engines, updated regularly with official signature files published by their respective developers.
This is a list of the companies that participate in VirusTotal with their antivirus engines.

VirusTotal also makes use of a number of file characterization tools:

 
This is indeed a very cool tool.

One thing to note about it though is that it runs the API versions of these AVs, and in most cases the API version isn't as good as the desktop version. So even if the website reports a file as clean your installed antivirus may still find a virus in it.

The reason for this is that its becoming more and more common for viruses/malware to encrypt themselves so antivirus can't detect them. Just looking at the file the virus looks like encrypted garbage. However when the virus runs it decrypts itself to memory and runs from there. Most good AVs monitor the memory and are able to catch it at this point though.

So its important to listen to your installed antivirus program -- it likely knows what its doing, even if virustotal tells you the file is clean.
 
This is indeed a very cool tool.

One thing to note about it though is that it runs the API versions of these AVs, and in most cases the API version isn't as good as the desktop version. So even if the website reports a file as clean your installed antivirus may still find a virus in it.

The reason for this is that its becoming more and more common for viruses/malware to encrypt themselves so antivirus can't detect them. Just looking at the file the virus looks like encrypted garbage. However when the virus runs it decrypts itself to memory and runs from there. Most good AVs monitor the memory and are able to catch it at this point though.

So its important to listen to your installed antivirus program -- it likely knows what its doing, even if virustotal tells you the file is clean.

Did not know this. Good call, dude!

Brian
 
One thing to note about it though is that it runs the API versions of these AVs, and in most cases the API version isn't as good as the desktop version.

Oh crap! :eek: I didn't know that. I thought they had some sort of VM setup where they ran it through an actual installed AV engine. Well...I guess it's better than nothing. :shrug:

Thanks for letting me know, I'll keep that in mind.

Did not know this. Good call, dude!

Brian
:thup:
 
Back