Comments on: Be Careful With VirusTotal https://davescomputertips.com/be-careful-with-virustotal/ Computer Help, Tips, How-to's, and News Mon, 25 Dec 2023 17:03:22 +0000 hourly 1 By: John Durso https://davescomputertips.com/be-careful-with-virustotal/#comment-141345 Mon, 25 Dec 2023 17:03:22 +0000 https://davescomputertips.com/?p=135903#comment-141345 In reply to Mindblower.

Hi Mindblower, thanks for the holiday greetings and wishing the same back.

I’m not mentioning a process. I’d say to reread the post. But, quickly, VT stores a copy of everything submitted and any paid VT user can view these.

So, say you get a email from your brother with 2 attachments. The first he tells you is a file he torrented from some site which promises to unlock that expensive piece of software you can not afford. The second is a self extracting archive file with the bitcoin keys repaying that $100,000 loan you gave him.

The first file you may have wanted to scan with VT. If you scan the second file with VT, thousands of extremely computer literate people in the VT community will have access to that file from the VT database and you may find that one of them transferred the bitcoin funds before you could.

]]>
By: Mindblower https://davescomputertips.com/be-careful-with-virustotal/#comment-141335 Sun, 24 Dec 2023 20:56:57 +0000 https://davescomputertips.com/?p=135903#comment-141335 Hello John. I am a bit confused. I used to have Virus Total as an addon, which would scan all exe files prior to downloading. Forget why I uninstalled it, other than finding it more of a time constraint when getting files in exe format from well known sites. Thought my software would warm me and block corrupted files.
So, is this process you are mentioning something new? This is where I get lost, Mindblower!
Merry Christmas and Happy New Year.

]]>
By: John Durso https://davescomputertips.com/be-careful-with-virustotal/#comment-141323 Sun, 24 Dec 2023 00:30:45 +0000 https://davescomputertips.com/?p=135903#comment-141323 In reply to Elliott W. Carmack.

Hi Eliott,
Everything I wrote in the article applies to that program which is just submitting your file to VirusTotal for you.

]]>
By: Elliott W. Carmack https://davescomputertips.com/be-careful-with-virustotal/#comment-141320 Sat, 23 Dec 2023 22:15:39 +0000 https://davescomputertips.com/?p=135903#comment-141320 Check out “VirusTotal Context Menu”, available at:
https://github.com/Genbox/VirusTotalContextMenu
OR
https://www.majorgeeks.com/files/details/virustotal_context_menu.html
After installing it, I right click on a file in File Explorer and have a “VT Scan” context menu entry, which I can use to scan the file.
Comment?

]]>
By: Peter Thompson https://davescomputertips.com/be-careful-with-virustotal/#comment-141317 Sat, 23 Dec 2023 18:11:03 +0000 https://davescomputertips.com/?p=135903#comment-141317 Interesting. Didn’t realise it was owned by Google so good to know.

I will add VirusTotal also doesn’t always show all results from AVs. AVs often use multiple layers of security and not all included in VirusTotal results.

I’ve also heard of cyber criminals trying to use it to determine if their malware is going to be flagged

]]>
By: John Durso https://davescomputertips.com/be-careful-with-virustotal/#comment-141296 Fri, 22 Dec 2023 23:15:13 +0000 https://davescomputertips.com/?p=135903#comment-141296 In reply to AJ North.

Thanks AJ, PeStudio just submits hashes of executable files to VT. Checking EXE’s, even the full file, in VT is probably safe since in most likely does not contain sensitive data. However, using something like PeStudio which just sends a hash will be faster then sending a file (assuming the executable is already in VT’s database) since you will not need to upload a whole file.

]]>
By: John Durso https://davescomputertips.com/be-careful-with-virustotal/#comment-141295 Fri, 22 Dec 2023 23:14:16 +0000 https://davescomputertips.com/?p=135903#comment-141295 In reply to Reg Watson.

Thanks for the comment Reg. Actually, in this case, it is not the corporates or governments that have data on you. If you load a file with sensitive data, it is the VT community. This could consist of a individual in his basement up to security experts in those corporations or governments. If you load a file with sensitive data in it, they can see it (and possible use it in negative ways).

]]>
By: AJ North https://davescomputertips.com/be-careful-with-virustotal/#comment-141292 Fri, 22 Dec 2023 21:20:05 +0000 https://davescomputertips.com/?p=135903#comment-141292 The portable app PeStudio is a convenient front-end to VirusTotal that allows one to simply drag and drop a file into it for analysis; it also provides additional useful information (free version available):
https://www.winitor.com/.

]]>
By: Reg Watson https://davescomputertips.com/be-careful-with-virustotal/#comment-141291 Fri, 22 Dec 2023 21:16:32 +0000 https://davescomputertips.com/?p=135903#comment-141291 Thanks John
The amount of data these behemoth corporations have on us is staggering already. They truly are the “evil empire”. Everything seems free until a tyrannical government working in partnership with these corporates decide to utilise the data they have on you. People may laugh but the more I learn the more I’m keeping my tinfoil hat firmly on !
Cheers
Reg

]]>