19
febrero
2007

VirusTotal += FileAdvisor

Bit9 product joins the service
[News] 
Bit9's FileAdvisor joins the list of engines included at VirusTotal. This is an interesting inclusion because of FileAdvisor nature: basically it works like a white list of legit applications. This can be very useful for people scanning samples that may look suspicious but that are in fact simply part of legit applications. Bit9 people is also including malware descriptions in their database, so it can also detect malicious samples. Although the report of this engine may not be very descriptive, in the additional information part of the report, in case of a positive detection, FileAdvisor will include an URL with a description of the scanned file.

Sent by jcanto @ 09:26 | Permalink | Comments (15) | Trackbacks (0)
Comentarios
Re: VirusTotal += FileAdvisor

"You searched for
MD5: 1234567890...

Your hash has been found in 12345... Package(s).

Click here to Login or Register to view more information."

I don't like to sign up!

"Not analyzed yet" should be greyed-out like "no virus found".

Posted by: Pete at febrero 19,2007 21:36
Comodo Antivirus

Hello,

Congratulation on your significant number of new engines that were added !!

Also I was wondering if you could add the Comodo Antivirus Engine since its quite good ??

Thanks

Al968

Posted by: alexandre at febrero 21,2007 23:14
Re: VirusTotal += FileAdvisor

I don't get this fileadvisor

Ok so I scan the mydoom worm on vt and results are
Ewido 4.0 02.21.2007 Worm.Mydoom.m
FileAdvisor 1 02.22.2007 Low threat detected
Fortinet 2.85.0.0 02.22.2007 W32/MyDoom.BB@mm

Fileadvisor say low threat detected
LOW!!!!!!! I thought mydoom was one of the biggest worms around

what a joke

Posted by: joe at febrero 22,2007 06:43
Re: VirusTotal += FileAdvisor

sahbdhsgsgdghsvdgsgdsddssatbdycgvfhf.

Posted by: chongchong at febrero 22,2007 12:53
Re: VirusTotal += FileAdvisor

1321

Posted by: cuong at febrero 23,2007 20:06
Re: VirusTotal += FileAdvisor

In response to joe..

"I don't get this fileadvisor"

Clearly.

From the OP:

"basically it works like a white list of legit applications"

If someone thinks the file is bad, but it is actually legit and apart of say firefox then it will tell them that it is apart of firefox instead of simply returning no result found.

I mean..did you even read the original post?

Posted by: IKT at febrero 28,2007 02:56
Re: VirusTotal += FileAdvisor

Yeah I did read it, im just confused to why it say low threat detected. goof

Posted by: joebob at marzo 06,2007 09:56
Please Update That Clamav engine

Hello, Can you please update the clamav engine

Reason: sometimes its not detecting viruses as it should, I run two version of clamav on my computer, the old version just like yours will NOT detect the file but the new version will detect the virus, this may have something to do with the f-level

Posted by: andy at marzo 14,2007 06:00
Re: VirusTotal += FileAdvisor

Thank You Jcanto for releasing 0.90.1 and fixing the problem i discribed in clamav mailing list

Posted by: sdfsdf at marzo 15,2007 07:21
Re: VirusTotal += FileAdvisor

i am fed up the virus and i went free downloading virus

Posted by: sa'id moh'ed at abril 15,2007 22:00
Re: VirusTotal += FileAdvisor

FileAdvisor is nothing else than a scam to get you to sign up to them and give them your particulars. Even then it's practically useless - stay away!

And shame to VirusTotal for taking part in this. I suggest you switch over to "Online malware scan" at http://virusscan.jotti.org/ until VirusTotal come to their senses and ditch FileAdvisor.

Posted by: Sancho at mayo 02,2007 08:27
Re: VirusTotal += FileAdvisor

lol omg OMG O M G FUCK YOU

Posted by: Idiota at mayo 16,2007 14:22
Re: VirusTotal += FileAdvisor

tìm hiểu các chương trình duyệt virust mới nhất

Posted by: Nguyễn phúc trí at julio 11,2007 05:28
Re: VirusTotal += FileAdvisor

eu quero remover todos os virus

Posted by: anderson. at agosto 19,2007 06:44
Re: VirusTotal += FileAdvisor

EICAR TEST FILE no reaction from FileAdvisor:)

Posted by: Moho at febrero 11,2008 13:34
Trackbacks
Please send trackbacks to: http://blog.hispasec.nospam/virustotal/19/tbZ3ping
Replace "nospam" with "com"
There are no trackbacks.
Post a comment