Share via

Is virustotal.com legimate ?

Anonymous
2017-03-29T05:10:05+00:00

I opened an email attachment from an spam email purportedly from the post office notifying me of a delivery, unfortunately I actually was expecting a package sent by Amazon so I got duped.   I confirmed with the post office the email was a fake.

McAfee suggested I test the file attachment using virustotal.com.    Virustotal.com listed 17 anti virus programs out of 40 that indicated the attachment was infected.  The McAfee program listed on virustotal.com did not identify the attachment as infected and this was confirmed when I actually did a full scan using McAfee.

I called the Microsoft consumer support department that deals with viruses and malware.   They did a number of scans that removed about 15 different malware programs, most or all of them minor.    None had names that matched the malware id'ed by virustotal.com.   When I asked about this, the Microsoft team ran virustotal.com on a barebones PC consisted of an operating system, and a browser.   Despite being a nearly empty system, virustotal.com identified a good number of malware on these barebones PC.  

Microsoft's conclusion:   virustotal.com is fake and randomly generates false lists of malware. (fyi, my MS contact was not familiar with virustotal.com.)

After assuring me, my system is secure, I checked the internet and discovered that virustotal.com was purchased by Google and seems respected.

My question is: is my PC secure.   Should I trust Microsoft and the McAfee scan or trust virustotal.com and do further malware scans elsewhere ????

Note: I also ran the MS Safety scanner and it  found no problem.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

15 answers

Sort by: Most helpful
  1. Anonymous
    2017-03-29T12:52:16+00:00

    Virustotal.com is an excellent program used to test individual suspect files and URL’s.  It is not used to scan a computer.

    Are you sure you talked with MS Support? 

    The phone number for Microsoft Support is 800-642-7676.  If you talked to anyone other thanhttps://www.microsoftstore.com/store/msusa/en_US/cat/Answer-Desk/categoryID.63433500 then you did not talk to Microsoft Support.

    Anyone not familiar with VirusTotal doesn't know very much about Virus & Malware issues. 

    Beware of Phony Tech Support Scams

    Fake Tech Support Scams – see video from the MS Digital Crimes Unit (copy/paste the link into your browser). https://www.youtube.com/watch?v=hQpm2ldzUno

    Suggest you run a scan with the Emsisoft Emergency Kit (a free program) http://blog.emsisoft.com/2015/06/09/how-to-find-and-clean-malware-infections-with-emsisoft-emergency-kit/ and then move on...the only way to be sure your Win 10 computer is free of any potential malware issues is a reset and you've said nothing in your post that indicates you need to do that. 

    As long as you’re paying McAfee for antivirus protection you should follow their advice. https://service.mcafee.com

    You may want to review the following - - -

    Best Practices for Safe Computing - Prevention of Malware Infection to include the articles on Choosing an Anti-Virus ProgramandSupplementing your Anti-Virus Program with Anti-Malware Tools

    Tips To Protect Your PC

    https://malwaretips.com/blogs/how-to-easily-avoid-pc-infections/

    Regards…

    And see http://blog.emsisoft.com/2015/01/27/top-10-ways-pups-sneak-onto-your-computer-and-how-to-avoid-them/

    Was this answer helpful?

    50+ people found this answer helpful.
    0 comments No comments
  2. Reza-Ameri 45,811 Reputation points Volunteer Moderator
    2017-03-29T20:53:40+00:00

    VirusTotal.com is safe website and normally we ask people to submit suspicious files there to see what are initial results. Each Anti-Virus vendor has it own submit sample portal, so in case you are using McAfee and it wasn't able to detect it, you may try submit sample to McAfee for test and they will investigate it and if they confirm that is a virus, then they will release signature to detect and remove it. You may contact McAfee support and keep in touch with them to submit sample and see the result of analysis.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2017-03-29T23:17:19+00:00

    Thanks for confirming virustotal.com is OK, but I'm confused by what I'm seeing. Actually, braced yourself,  I am shocked as I'll explain below after I answer your questions:

    First, I am certain I called Microsoft at this number to use from Canada 1 877 568 2495.  In November, I purchased one year of tech support.   I did not pay for the support I received.   Curiously I note that when I do a call display  on my phone the number displayed is not  877 568 2495, but displays 800-642-7676 which is the number you suggested.  Also curious is that we end session 1 and took a break: my callback display is not listing the call back from MS at all.  

    If my MS contact was not aware of virustotal.com it might be a training issue?.    My MS contact is in the Phillipines.  Is there a time of day I can call and get a US mainland contact?

    About McAfee.  My license with McAfee allows use only of their software.   They would not accept my suspicious file for their analysis. That is why they suggested virustotal.com,  as an alternative.

    The Emisoft emergency scan (the malware version) found no issuesseemingly confirming my MS support contact's judgement.

    Now the problem is I am  beginning to suspect my Microsoft Phillipine contact is corrupt.   My original scan by virustotal on Mar 25 listed 17 programs out of 56 found issues.   Today's scan found 30 programs listing issues.

    My phone call with Microsoft was on Mar. 27.  Here are print screens of the virustotal  reports :

    BEFORE

    AFTER:

    Now there is another bit of data:  I have a malware detecting program called Trusteer Rapport that also checks for malware activity,   It was provided by my bank, so I trust it.    It listed 5 suspicious activities that happened while I was in contact with Microsoft support.   Here is a print screen of that ![](https://learn-attachment.microsoft.com/api/attachments/e88d4484-a770-44bd-b5a8-394e76b38106?platform=QnA)

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2017-03-30T21:57:34+00:00

    I did not research the Trusteer detections.  But clicking the iexplore.exe link you sent me, led me to download the Malwarebytes premium trial, and I'm using it to do a scan right now.     A little strange is that after I started Malwarebytes premium, I tried clicking the link again and then the link Click to Run a Free Scan for iexplore.exe related errors in the file.com website, Malwarebytes responds with a screen that says 'Malwarebytes has blocked a potentially malicious website'.   I assume this is a false positive.

    Back to my original issue, the full custom scan of Emsisoft did identify the file I was suspicious of as high risk.  But before quarantining it, I then did a full McAfee scan and was disappointed to see that it still did not id the file as suspicious (even though virustotal.com indicated McAfee flagged it as malicious). 

    I have now quarantine the file using Emsisoft.  But one question still remains.    Emsisoft flagged the copy of the file I stored in a folder.   It did not flag the original file that is an attachment in an email.   Is that acceptable?

    A second concern I have, is that I know I activated the malicious file.   It could already have disseminated sensitive information from my system.    Fortunately I did not do any sensitive transactions such as banking or credit card recently, so that limits the potential damage somewhat.

    The Malwarebytes just completed.   It found zero threats, again not discovering the email attachment mentioned above.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2017-03-30T00:01:48+00:00

    I just realized I was not thinking clearly.   The increase in programs detecting an issue with the suspicious file indicates that other programs have changed to be more sensitive the malware at issue, not  that Microsoft infected my system as I supposed.    So my concern has decreased, but not gone.   I plan to do a custom scan with Emisoft overnight (not sure if takes a long time).

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments