Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 2nd, 2010, 01:02 PM
EscapeVelocity EscapeVelocity is offline
Frequent Poster
 
Join Date: Apr 2010
Posts: 368
Default Tips on reading VirusTotal results

How do you read VirusTotal, if any of the 40 or so results is positive its dirty? Or do you require more than one positive?

Thanks
__________________
.
Avast Free 5.0 - All Shields Up
  #2  
Old May 2nd, 2010, 01:03 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Tips on reading VirusTotal results

one will be more than enough for me not to trust any file that is me
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #3  
Old May 2nd, 2010, 01:07 PM
AvinashR's Avatar
AvinashR AvinashR is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: New Delhi Metallo β-Lactamase 1
Posts: 2,060
Default Re: Tips on reading VirusTotal results

Above 10 would be good...
__________________
∆√♪ηάکђ
ℓєтک υηcσммpℓιcαтє
http://www.adminus.net
http://technonxt.wordpress.com
  #4  
Old May 2nd, 2010, 01:09 PM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: Tips on reading VirusTotal results

Quote:
Originally Posted by EscapeVelocity
How do you read VirusTotal
Thanks

With a pinch of salt :-)

Check what imports the file has, if there is a ThreatExpert report on it, and what hit(s) google has for that MD5.
  #5  
Old May 2nd, 2010, 01:23 PM
EscapeVelocity EscapeVelocity is offline
Frequent Poster
 
Join Date: Apr 2010
Posts: 368
Default Re: Tips on reading VirusTotal results

Here is a VirusTotal report with 5 positives on ~Link removed. See the Policy.~ Combofix download[/url]...
__________________
.
Avast Free 5.0 - All Shields Up
  #6  
Old May 2nd, 2010, 01:25 PM
EscapeVelocity EscapeVelocity is offline
Frequent Poster
 
Join Date: Apr 2010
Posts: 368
Default Re: Tips on reading VirusTotal results

Ooops.
__________________
.
Avast Free 5.0 - All Shields Up
  #7  
Old May 2nd, 2010, 01:40 PM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,395
Default Re: Tips on reading VirusTotal results

Agree, and check which scanner is giving the result. If it's symantec, giving the only report, I usually rate that higher over a smaller AV which might have far more false positives.
__________________
Fine Art Landscape Photography
  #8  
Old May 2nd, 2010, 02:07 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Tips on reading VirusTotal results

You might like this write-up
http://blog.didierstevens.com/2008/0...s-detect-this/
as posted
http://www.wilderssecurity.com/showthread.php?t=208007
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #9  
Old May 2nd, 2010, 02:11 PM
ALiasEX ALiasEX is offline
Frequent Poster
 
Join Date: Mar 2010
Posts: 240
Default Re: Tips on reading VirusTotal results

Quote:
Originally Posted by Saraceno
Agree, and check which scanner is giving the result. If it's symantec, giving the only report, I usually rate that higher over a smaller AV which might have far more false positives.
Unless the detection is Symantec.Insight. They should remove that from the engine used by VirusTotal.
  #10  
Old May 2nd, 2010, 02:11 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,224
Default Re: Tips on reading VirusTotal results

I always take my final decision on me, i mean even if a few AV's flagged it as malware and i know this file is clean i consider it clean. (Based on other aspects)

Of course if lots of AV's flagged it as malware i won't open it
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #11  
Old May 5th, 2010, 05:49 AM
doktornotor's Avatar
doktornotor doktornotor is offline
Very Frequent Poster
 
Join Date: Jul 2008
Posts: 2,045
Default Re: Tips on reading VirusTotal results

Quote:
Originally Posted by Noob
I always take my final decision on me, i mean even if a few AV's flagged it as malware and i know this file is clean i consider it clean. (Based on other aspects)

Well, funny that you mention this. It seems that AV vendors have completely lost their sense of humour. The bellow are the results for completely innocent PlaceboAV joke. Leaving the other misclassifications aside, one strikes me really. Fraudtool?! Looks like the mankind is doomed if someone buys this product.

~Virus Total results removed per Policy~

Last edited by ronjor : May 5th, 2010 at 08:46 AM. Reason: Virus Total results removed
  #12  
Old May 5th, 2010, 06:27 AM
NoIos NoIos is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 607
Default Re: Tips on reading VirusTotal results

If the first submission of the file is really recent then my opinion is that the results have no value at all.

- If the file is known to virustotal for more than a week-10 days, then you can start to trust the results.
- Check what Ikarus says since it seems the more "honest" AV out there, specially if your file is a high risk file, like a keygen/patch.
- Check if the rest of the AVs agree about the file.
- Compare what signature based AVs say and what those that have a cloud technology.
- Then...check what ThreatExpert has to say.
- At the end...ok, you know it...you cannot be sure 100%. So ignore virustotal and run the file on an isolated virtual machine or using software like shadow defender. Sandboxie could be an option too.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:49 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums