VirusTotal getting annoying cause of FPs

Checking executables

I thought I'd post a way of checking any new unsigned executables that attempt to run anywhere on your system but just for information purposes and not to suggest that it's a good idea to install this software. I've been using it for some time. There's a one year free license.

https://secureaplus.secureage.com/Main/secureaplus_download.php

Personally I use the offline No AV version. Once installed the initial scan of executables that are already present on your system takes around an hour or more. Those executables will be whitelisted.

What happens when an unsigned executable attempts to run - you get the option to block it:

SecureAPlus.jpg

The file gets scanned on VirusTotal and the result is shown.

SecureAPlus2.jpg

Configuration options:

Prompt when a file is not in the whitelist
SecureAPlus Settings 1.jpg

Trust the file based on digital signature if it's in the trusted list
SecureAPlus Settings 2.jpg

Disable AV and rely on your installed AV or optionally enable/ disable it when needed for a secondary scan
SecureAPlus Disable AV.jpg

Add any application capable of downloading/ creating executables to the restricted application list.

Typically:

Any/all web browsers installed on your computer
Entire MS Office suite (Access, Excel, Outlook, PowerPoint, Word)
Sun (now Oracle) Java
Any media player (Windows Media Player, VLC, iTunes, RealPlayer, QuickTime, Winamp)
Any software that waits and listens for a network connection
Any Adobe product that you see frequently listed within Adobe's Security bulletins and advisories.

No need to add flash player - the plugin is protected by adding the browser's executable.

Add restricted.jpg

When installing trusted software there's an option to "Trust All"
Change mode.jpg

There's also the option to change trust level for any executable on your system
Change Trust Level.jpg

I feel that it does add an additional layer of security but it doesn't seem to get mentioned often here on SevenForums. I guess that it suits users who wish to be kept informed of what's going on on their system and who don't mind responding to pop ups. I like pop ups!
 
Last edited:

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
I'll have a look at Metascan, but is it as frequently used as VT? I don't know, but one of best things with sigcheck and VT is that it almost never have to submit any files because someone else has already done it, including recently updates files. Checking thousands of files only takes a few minutes.
MetaScan has been arounf for a bit, I don't see why it wouldn't get as much usage as VT. It works on exacly the same principle as VT.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Thanks for the input guys!

And thanks for all the screenshots Callender, much appreciated!
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Opswat Metascan

I'll have a look at Metascan, but is it as frequently used as VT? I don't know, but one of best things with sigcheck and VT is that it almost never have to submit any files because someone else has already done it, including recently updates files. Checking thousands of files only takes a few minutes.
MetaScan has been arounf for a bit, I don't see why it wouldn't get as much usage as VT. It works on exacly the same principle as VT.

Sometimes I've used the MetaScan File Uploader

It does seem very similar to VirusTotal.

I also installed Gears from the same company:

Opswat Gears

I removed it as it crashed my machine. I couldn't be bothered to figure out why.

I do find their browser add on very useful though:

http://www.sevenforums.com/browsers-mail/349908-metascan-firefox-add-released.html

Also available for Chrome.

Scans connections, downloads and ip addresses.

I just like to add additional security if it works without slowing things down too much!
 
Last edited:

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Yep....its a brilliant little add-on for a browser :thumbsup:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top