Check it against seventy antivirus engines in about two minutes. Free, and you don't need to install anything.
Already sent money or typed in a password?
Skip all of this and call (720) 295-3735. The first 72 hours decide how much comes back.
01
VirusTotal is a free service owned by Google. It runs your file or link past dozens of antivirus engines at once and shows you what each one said.
You clicked a link
Copy the web address and paste it in. You don't need to visit it again.
Check a link ↗, opens in a new tabYou downloaded a file
Drag the file you already have onto the page. Don't open it.
Check a file ↗, opens in a new tabDon't open or run the file again to find it. Use the copy you already have.
Anything you upload can be downloaded by security researchers and by VirusTotal's paying customers. Don't upload tax returns, medical records, or anything with personal details in it. For those, call (720) 295-3735 and we'll check it a different way.
02
You'll get a count, like 3/72. That's how many engines flagged it out of how many looked.
Nothing was flagged
Encouraging, but it is not proof. Antivirus engines recognise malware they have already seen. Brand-new and targeted malware routinely shows little to no detections.
Open the Details tab and find First seen. If VirusTotal only met this file minutes ago, treat a clean result with more caution, not less.
Carry on to step 03 either way.
Something was flagged
One or two detections out of seventy, from engines you've never heard of, is usually a false alarm — especially on small programs and installers.
A screen full of red is not. That means it's a threat the industry already knows by name, which also means there's a real chance your own antivirus stopped it. Step 03 is how you find out.
03
Malware doesn't do everything at once. It moves in stages — the first click, then a download, then digging in to survive a restart — and it has to get past your defences at every one. An alert in the log can mean it was stopped partway through. What you check depends on what you clicked.
A file — on Windows
Look at what Windows already caught, then sweep the whole disk.
An entry marked Quarantined or Removed is a good sign. It is not the same as confirmation that nothing got through — leave those alerts in place so we can read them.
On a Mac, none of the above exists. Call us and we'll check it with you.
A link where you signed in
Assume the password is gone and work outward from there.
A convincing fake page can take more than the password — session cookies let someone stay signed in without it. Watch that account's login alerts for the next few weeks.
A full scan takes a while. While it runs, don't sign in to banking on that machine, and don't uninstall or delete anything yet — if there is something there, we'd rather look at it where it sits.
04
Grab one thing from VirusTotal first. Click the Details tab, then look under Basic properties.
For a file
Copy the MD5, SHA-1, or SHA-256 value.
For a link
Copy the Last DNS records table.
A hash is a fingerprint. It identifies the file without being the file, so it's safe to email. And writing a bad link as example[.]com makes it un-clickable, so nobody opens it by accident.
If your email app didn't open
Nothing has been sent yet — your computer has to do that part. Copy the message below and email it to contact@acornsecurity.net, or just call (720) 295-3735 and read it to us.
05
Back in VirusTotal, the Behavior tab shows what the file actually did when it was run in a sandbox — files it wrote, addresses it called. The Community tab shows what other researchers made of it.
Searching the file name or the hash often turns up a full write-up from someone who has already taken it apart.
Nothing wrong this time?
Two more free tools, about ten minutes each.
Sent money or typed in a password? Don't wait.
Call (720) 295-3735Not urgent, but you'd rather someone looked?
Book a free 30 minutes ↗