
To check a file for viruses online, upload it to a multi-engine scanner such as VirusTotal, or better, search for its SHA-256 hash first so the file never leaves your machine. A clean hash report from 70+ engines is a strong signal; one or two obscure detections usually are not. Never upload confidential documents.
Free online virus scanners worth using
There are two kinds of online scanners. Aggregators run a file through dozens of engines from different vendors at once. Single-vendor portals use one company's signatures and heuristics but tend to explain their verdict better. For a one-off check, both are free and need no installation.
VirusTotal
VirusTotal, owned by Google, collects verdicts from more than 70 antivirus engines, including Microsoft Defender, Kaspersky, ESET, Bitdefender and Sophos. Drop a file on the File tab, paste a link on the URL tab, or paste a hash on the Search tab. The web interface accepts files up to 650 MB. Beyond the detection count, the report has Details (hashes, code signature, first submission date), Relations (domains and IPs the file talks to) and Behavior (sandbox activity, when available).
Kaspersky OpenTIP
Kaspersky Threat Intelligence Portal looks up files, hashes, URLs, domains and IPs against Kaspersky's detection technology and its KSN reputation data. It returns a zone (Good, Bad, Not categorized) plus the detection name, which is handy when you want one well-known vendor's opinion spelled out.
MetaDefender Cloud and Hybrid Analysis
MetaDefender Cloud by OPSWAT is another multi-engine scanner and a useful second opinion when VirusTotal is borderline. Hybrid Analysis detonates the sample in a sandbox and shows what it actually does: processes spawned, registry keys touched, network connections. Its reports are public, so the same privacy rules apply.
How the options compare
| Option | Engines | Accepts | Who can see your file | Best for |
|---|---|---|---|---|
| VirusTotal | 70+ | Files up to 650 MB, URLs, domains, IPs, hashes | Security community and paying customers | First check of installers, archives, APKs |
| Kaspersky OpenTIP | One vendor + KSN reputation | Files, hashes, URLs, domains, IPs | Kaspersky | A single named verdict with context |
| MetaDefender Cloud | Multiple | Files, hashes, URLs, IPs | OPSWAT and its users | Second opinion on a borderline file |
| Hybrid Analysis | Sandbox + reputation feeds | Files, URLs | Public report | Seeing what a file actually does |
| Hash lookup only | Depends on the service | A SHA-256 string | Nobody — the file stays local | Confidential or very large files |
| Local antivirus | One vendor | Any size, archives, folders | Nobody (unless sample submission is on) | Files over 1 GB, bulk scans |
Check a file by its SHA-256 hash without uploading it
A hash is a fingerprint: change one byte and the whole value changes. If anyone has already submitted the same file, VirusTotal and OpenTIP will return the existing report from the hash alone. For popular installers, drivers and ISO images that is almost always the case. Hashes also let you verify a download against the checksum the vendor publishes next to the link.
Windows Command Prompt:
certutil -hashfile C:\Users\you\Downloads\setup.exe SHA256
Windows PowerShell (SHA-256 is the default algorithm):
Get-FileHash .\setup.exe -Algorithm SHA256
Linux:
sha256sum setup.exe
macOS:
shasum -a 256 setup.exe
Paste the 64-character result into VirusTotal search, or open https://www.virustotal.com/gui/file/<hash> directly. "Item not found" does not mean clean — it means nobody has uploaded that exact file. That is normal for a niche tool or your own build, and suspicious for what claims to be the official installer of a mainstream app. See Microsoft's reference for Get-FileHash for the full syntax.
Reading the report: is 1/70 a virus?
The number on its own is the least useful part of the report.
- One or two hits out of 70 from lesser-known engines, while the major vendors say clean, is usually a false positive. Heuristics tend to flag packers, self-extracting installers, AutoHotkey scripts and unsigned utilities.
- Five or more hits including Microsoft, Kaspersky, ESET or Bitdefender: do not run it.
- The detection name matters more than the count.
PUA,PUP,Adware,Riskwareand Kaspersky'snot-a-virus:prefix mean "unwanted", not necessarily malicious — bundled adware, remote-access tools, key generators.Trojan,Backdoor,RansomandStealermean stop. Generic,Gen:andHEUR:are heuristic verdicts without a specific signature. A lone one is a reason to dig deeper, not to panic.- Code signature on the Details tab: a valid certificate from a known publisher lowers the risk; no signature on a supposedly official installer raises it.
- First Submission date: an installer that supposedly shipped last year but was first seen yesterday has probably been repackaged.
You can check the signature locally too. In PowerShell, Get-AuthenticodeSignature .\setup.exe should report Valid. Sysinternals Sigcheck with sigcheck -v setup.exe prints the signature and looks the hash up on VirusTotal in one go.
A clean report is not a guarantee. A brand-new sample can pass every engine before signatures catch up, so treat online scanning as a first filter for software from untrusted sources, not a final answer.
Privacy: what you should never upload
Files submitted to VirusTotal are shared with the security community and its paying customers, as its Terms of Service state. A researcher with a subscription can download your contract, bank statement or passport scan, and anyone can find it by hash or file name.
- Do not upload documents containing personal data, contracts, financial reports, customer lists, or config files with passwords and API keys.
- For those, use a hash lookup or a local scan only.
- If your organisation has a policy on external file sharing, it almost certainly covers online scanners too.
Scanning large files (over 1 GB)
Online scanners are not built for disk images, game repacks or multi-gigabyte archives. Instead:
- Hash it and search. Official images and distributions nearly always have a report already.
- Extract the archive without running anything. Malicious code lives in executables and scripts (
.exe,.dll,.msi,.bat,.ps1,.js,.scr), not in textures or video. Those files are small; upload them individually. - Scan locally. A local engine has no size limit.
Microsoft Defender can scan a single file from an elevated prompt:
"%ProgramFiles%\Windows Defender\MpCmdRun.exe" -Scan -ScanType 3 -File "D:\Downloads\archive.zip"
Or from PowerShell:
Start-MpScan -ScanType CustomScan -ScanPath "D:\Downloads\archive.zip"
The same is available in File Explorer via right-click → "Scan with Microsoft Defender". All switches are documented in Microsoft's command-line reference.
On Linux and macOS, ClamAV is free:
sudo freshclam
clamscan -r --infected ~/Downloads/archive/
-r scans recursively; --infected prints only infected files.
File types that need extra care
Executables and installers
The riskiest category. Work through it in order: hash, VirusTotal report, code signature, then compare the hash with the one on the vendor's site. Cracks, keygens and "activators" are flagged by nearly every engine, and there is no way to tell a false positive from a real trojan inside one — keep them off any machine you care about.
ZIP, RAR and 7z archives
Scanners unpack ordinary archives themselves. Password-protected ones they cannot: only the container gets scanned and the report looks clean. Extract to a separate folder and scan the contents. An encrypted archive from a stranger with the password in the email body is a classic way to slip past mail filters.
Android APKs
VirusTotal accepts APKs and lists the requested permissions under Details. With the Android SDK build tools installed, verify the signing certificate:
apksigner verify --print-certs app.apk
A certificate different from the Google Play build means someone else rebuilt the app. On the phone itself, open virustotal.com in a browser and upload the APK from Downloads before installing it.
Office documents and PDFs
The danger is macros and embedded objects. Treat .docm, .xlsm and legacy .doc/.xls attachments with suspicion, and never click "Enable Content" just because the document asks you to.
Checking a download link before you click
Most malicious files arrive as links, not attachments. Check both the link and whatever it downloads.
- Copy the address via right-click → "Copy link" instead of opening it.
- If it is a short link, expand the redirect chain and look at the final destination.
- Check the domain against antivirus and safe-browsing blocklists, and look at its registration date: a week-old domain imitating a bank or a software vendor is a textbook phishing sign. Google's Safe Browsing site status page is another quick lookup.
- If the link points straight at a file, download it without opening and check it as described above.
How to check
enterno.io does not accept file uploads — use the services in the table for that. The link you were sent can be checked here:
- URL and website malware check — looks the address up in dozens of antivirus and safe-browsing databases.
- Redirect checker — expands a short link and shows where it really ends up.
- Domain WHOIS — registration date and registrar; a fresh domain behind an "official" download is a red flag.
If it is your own site that got infected, the playbook is different — see how to check a website for malware. Red flags of fake sites are covered in how to check a website for fraud, why a single antivirus is sometimes not enough in EDR vs antivirus, and what to do if your domain lands on a blocklist in site blacklist check.
FAQ
Is VirusTotal safe to use?
It is safe for scanning, but not private: uploaded files are shared with security researchers. Use hash lookups for anything confidential.
How many detections on VirusTotal mean a file is malicious?
There is no fixed threshold. One or two hits from minor engines with the big vendors clean is likely a false positive. Several hits including Microsoft, Kaspersky or ESET labelled Trojan or Backdoor means infected.
How do I scan a file larger than 650 MB?
Search its SHA-256 hash first. If there is no report, scan it locally with Defender or ClamAV, or extract the archive and upload only the executables.
Why does a scanner show nothing for my password-protected ZIP?
It cannot decrypt the archive, so only the wrapper is scanned. Extract the files and scan them individually.
Can I check a file for viruses on my phone?
Yes. VirusTotal and OpenTIP work in a mobile browser; pick the file from Downloads with the upload button. For APKs, do this before installing.