Weird message from VirusTotal

Discussion in 'other anti-malware software' started by nine9s, Apr 29, 2019.

  1. nine9s

    nine9s Registered Member

    Joined:
    Feb 8, 2013
    Posts:
    310
    Location:
    USA
    It has a pictures of a purple blob thing and states:

    Oops, I know nothing about this item.
    Hi there, my name is Win32.Helpware.VT... certain antivirus labs also call me W32.eHeur.BadNews.GAFE, I guess it is because every time I appear they get very upset. It looks like you found a hole in my malware net...

    The request failed with status code: 404


    While having it scan an Excel file a Board of Directors of a HOA sent me. I ran it twice and it did it both times. Before it did it, all the engines were giving green check-mark okays on the scans. Then toward the end of the scans it just displays the above on a screen.

    Any ideas what this is? I deleted the file I was scanning and never opened it but it did download from a email.
     
  2. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    I had similar problem today while scanning executable file. IMO there is a problem with their service (or one of the engines) and in that case they show that error.
     
  3. nine9s

    nine9s Registered Member

    Joined:
    Feb 8, 2013
    Posts:
    310
    Location:
    USA
    I scanned two files. One resulted in that message; the other did not. I ran the one, that had that result, a second time and it had that result again.

    I also ran some links through VirusTotal and all were normal with no such result.

    I deleted the files - and never opened them. I have Emsisoft on my PC and I am now running a thorough, including rootkit search, scan with the free Malwarebytes and will follow up with an Emsisoft scan and download a Microsoft virusscanner and use it.
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Here is my error if I try to rescan that file (it's already uploaded so no upload needed, just using their rescan option) :

    upload_2019-4-29_18-15-51.png

    I don't think you should worry about anything.
     
  5. nine9s

    nine9s Registered Member

    Joined:
    Feb 8, 2013
    Posts:
    310
    Location:
    USA

    Yes that is the exact site result I got. I am not sure if he is friendly or nefarious :)

    Would the 404 result mean Virustotal was trying to follow a link in the file but got a DNS error?

    BTW, Malwarebytes found nothing on my system.
     
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes it seems as if VT doesn't find URL with hash when trying to show final results. If I scan the same file again results from previous scan are shown (with correct time of last scan).
     
  7. nine9s

    nine9s Registered Member

    Joined:
    Feb 8, 2013
    Posts:
    310
    Location:
    USA
    I just tried a VirsusTotal scan of 3 day old unrelated PDF file on my PC and it resulted in the same purple blob thing message.

    Then I created a PDF of one page print of a simple Google search result page. VirsusTotal gave the same purple blob result from scanning it.
     
  8. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    97,890
    Location:
    U.S.A.
    FYI. https://en.wikipedia.org/wiki/HTTP_404
     
  9. nine9s

    nine9s Registered Member

    Joined:
    Feb 8, 2013
    Posts:
    310
    Location:
    USA
    Reading that, I wonder if that is the result from one of the scanning engines that VirusTotal uses? It looks too low-level/low budget picture for a Google/Alphabet company, like VirusTotal, to use. So I wonder if there is some snafu and VT is just passing that particular engine's error result instead of its normal reporting of each engine's result.
     
  10. nine9s

    nine9s Registered Member

    Joined:
    Feb 8, 2013
    Posts:
    310
    Location:
    USA
    Ok I ran a bunch of scans on my system.

    Malwarebyes custom scan, including rootkits: nothing
    Emisosft full scan: nothing
    Emsisoft rootkit and direct disk access scan: nothing
    Microsoft Virus scanner (MSERT - MicroSoft Emergency Response Tool) full scan, from a just downloaded version: nothing

    Safe?
     
  11. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.