File - List of Engines

Identifying files according to antivirus detections

The main search box also allows you to specify a full or partial malware family name ( Backdoor.Win32.PcClient!IKSalityMydoom.R), or any other text you want to find inside the antivirus reports. However, this kind of search will look at all indexed fields for the file, it will not only focus on the antivirus results. In order to focus exclusively on the antivirus results (no matter which particular engine produced the output), you should use the engines prefix. For example:engines:"Trojan.Isbar"or engines:"zbot".

Identifying Antivirus Engines

If you are looking for files detected by some specific antivirus vendor you can make use of vendor prefixes. These prefixes should preceed your keyword in order to restrict the scope of the search to a particular antivirus solution, for example: symantec:infostealermcafee:rahackf-secure:virut.

Identifying Antivirus Symantec

By using vendor prefixes you can also search for all files detected by a given vendor, independently of the malware name. To do this you must write the vendor prefix followed by the special keyword infected, e.g. ESET-NOD32:infected. In this case the word infected does not necessarily have to be present in the antivirus signature, it is just indicating that the file must be detected. Similarly, you can list all files not detected by some antivirus by using the keyword clean. For example:ESET-NOD32:clean.

Identifying Antivirus Clean

 

This is the full list of allowed vendor prefixes:

acronisad_awareaegislabahnlab
ahnlab_v3alibabaalyacantivir
antivir7antiy_avlapexarcabit
avastavast_mobileavgavira
avwarebabablebaidubitdefender
bitdefenderfalxbitdefenderthetabkavbkav_pro
cat_quickhealclamavcmccommtouch
comodocrowdstrikecybereasoncylance
cynetcyrendeepinstinctdrweb
egambitelasticemsisoftendgame
escaneset_nod32f_protf_secure
fireeyefortinetgdatagoogle
gridinsoftikarusinvinceajiangmin
k7antivirusk7gwkasperskykingsoft
lionicmalwarebytesmaxmaxsecure
mcafeemcafee_gw_editionmicrosoftmicroworld_escan
nano_antivirusnod32nprotectpaloalto
pandaprevx1qihoo_360rising
sangforsentinelonesophossunbelt
superantispywaresymantecsymantecmobileinsighttachyon
tencentthehackertotaldefensetrapmine
trendmicrotrendmicro_housecalltrustlookvba32
vipreviritvirobotwebroot
whitearmoryandexzillyazonealarm
zoner

The list is subject to changes as new antivirus solutions are integrated in VirusTotal and existing ones change names so do not forget to visit it every once in a while.

Back to Top