ACORN SECURITY

Is this file or link safe?

Check it against seventy antivirus engines in about two minutes. Free, and you don't need to install anything.

Already sent money or typed in a password?

Skip all of this and call (720) 295-3735. The first 72 hours decide how much comes back.

01

Submit it for analysis.

VirusTotal is a free service owned by Google. It runs your file or link past dozens of antivirus engines at once and shows you what each one said.

You clicked a link

Copy the web address and paste it in. You don't need to visit it again.

Check a link, opens in a new tab

You downloaded a file

Drag the file you already have onto the page. Don't open it.

Check a file, opens in a new tab

Don't open or run the file again to find it. Use the copy you already have.

Anything you upload can be downloaded by security researchers and by VirusTotal's paying customers. Don't upload tax returns, medical records, or anything with personal details in it. For those, call (720) 295-3735 and we'll check it a different way.

02

Read the answer.

You'll get a count, like 3/72. That's how many engines flagged it out of how many looked.

Nothing was flagged

Encouraging, but it is not proof. Antivirus engines recognise malware they have already seen. Brand-new and targeted malware routinely shows little to no detections.

Open the Details tab and find First seen. If VirusTotal only met this file minutes ago, treat a clean result with more caution, not less.

Carry on to step 03 either way.

Something was flagged

One or two detections out of seventy, from engines you've never heard of, is usually a false alarm — especially on small programs and installers.

A screen full of red is not. That means it's a threat the industry already knows by name, which also means there's a real chance your own antivirus stopped it. Step 03 is how you find out.

03

Check whether it got any further.

Malware doesn't do everything at once. It moves in stages — the first click, then a download, then digging in to survive a restart — and it has to get past your defences at every one. An alert in the log can mean it was stopped partway through. What you check depends on what you clicked.

A file — on Windows

Look at what Windows already caught, then sweep the whole disk.

Open Windows Security, then Virus & threat protection.
Open Protection history. Look for anything dated between the moment you clicked and now.
Back on Virus & threat protection, choose Scan options, then Full scan.

An entry marked Quarantined or Removed is a good sign. It is not the same as confirmation that nothing got through — leave those alerts in place so we can read them.

On a Mac, none of the above exists. Call us and we'll check it with you.

A link where you signed in

Assume the password is gone and work outward from there.

Change that password — and change it anywhere else you used the same one.
Open the account's recent sign-in activity. Look for places and devices you don't recognise.
Remove any connected app, forwarding rule, or extra user you did not add yourself.

A convincing fake page can take more than the password — session cookies let someone stay signed in without it. Watch that account's login alerts for the next few weeks.

A full scan takes a while. While it runs, don't sign in to banking on that machine, and don't uninstall or delete anything yet — if there is something there, we'd rather look at it where it sits.

04

Send it to us and we'll tell you what to do next.

Grab one thing from VirusTotal first. Click the Details tab, then look under Basic properties.

For a file

Copy the MD5, SHA-1, or SHA-256 value.

For a link

Copy the Last DNS records table.

A hash is a fingerprint. It identifies the file without being the file, so it's safe to email. And writing a bad link as example[.]com makes it un-clickable, so nobody opens it by accident.

Whatever you know. The button fills in a starting shape for you.

You'll normally hear back within one business day.
If it's more urgent than that, call (720) 295-3735.

We use your name and email to answer you and nothing else. No list, no sharing, no charge.

05

Or look deeper yourself.

Back in VirusTotal, the Behavior tab shows what the file actually did when it was run in a sandbox — files it wrote, addresses it called. The Community tab shows what other researchers made of it.

Searching the file name or the hash often turns up a full write-up from someone who has already taken it apart.

Sent money or typed in a password? Don't wait.

Call (720) 295-3735

Not urgent, but you'd rather someone looked?

Book a free 30 minutes