Submitted by patteoks on 2018/11/05 10:00
Bkav W32.eHeur.Malware09 20181102
DrWeb BACKDOOR.Trojan 20181105
VBA32 BScope.Trojan.VBKrypt
20181105

Comments

hi patteoks,
I'm using the latest portable version, and have been using IQ for years. So, no, I would not worry about this.
Was it the portable or installer version you tested?

patteoks

2018/11/05 10:22

In reply to by Tom

Both the Installer and the Portable version displayed the same warnings.

I have just downloaded both versions and scanned the .ZIP files with Windows Defender, AVG and Sophos and nothing comes up.
 

patteoks

2018/11/05 10:45

In reply to by Paul_J_Miller

Yes, I know that Windows Defender and Malwarebytes also says it's clean.
 
A few years back, I had some trouble with a rather persistent malware infection. As a result, I take the precaution to check each download against Virustotal which will automatically submit the file to a whole series of antivirus vendors for scanning.
 
A few positives may not mean anything as they could be false positives.
 
Just want to be on the safe side which is why I generally send downloaded files to
 
 
which was own previously by Google and now Alphabet Inc.

[quote=patteoks]
Bkav W32.eHeur.Malware09 20181102
DrWeb BACKDOOR.Trojan 20181105
VBA32 BScope.Trojan.VBKrypt
20181105
[/quote]
Hi patteoks,
 
First, a warm welcome to the IQ community web site
 
Quote from the VirusTotal forum
 
[quote]
VirusTotal simply aggregates the output of different antivirus vendors and URL scanners, it does not produce any verdicts of its own. As such, if you are experiencing a false positive issue, you should notify the problem to the company producing the erroneous detection, they are the only ones that can fix the issue. Please note that even if we were able to remove the flag, the users of such product would still be blocked from accessing your site.
[/quote]
 
I scanned the portable version and got 2 warning for the IQURI protocol install. It is a text file which modifies the registry to enable universal links. I guess it can be seen as malware, but it isn't.
 
As for the 3rd, it is the main program, infoqube.exe. I submitted it to DrWeb as false positive. Hopefully, they'll confirm that and add it to their signatures
 
HTH !
 
Pierre_Admin
IQ Designer
 

Pierre_Admin

2018/11/05 14:51

In reply to by Pierre_Admin

The file was verified and found to be a false alarm:
[quote]
Greetings,
 
Your request has been analyzed. It was a false alarm. The error was fixed.
 
Thank you for the cooperation.
 
Чтобы получать оповещения на русском языке, отправьте пустое сообщение на адрес lang@rt-web.dev.drweb.com
 
--
Yours sincerely,
Virus Monitoring Service
Doctor Web Ltd.
[/quote]
 
Pierre_Admin
IQ Designer
 

patteoks

2018/11/08 23:20

In reply to by Pierre_Admin

I have just downloaded the latest version released on 08 Nov 2018. Looks like Dr Web did not fix the false alarm.
 
I'm not going to worry about it.
 
But I just thought you might want to contact them again as this might deter others from trying out InfoQube.
 
Bkav W32.eHeur.Malware09 20181108
DrWeb BACKDOOR.Trojan 20181109
VBA32 BScope.Trojan.VBKrypt 20181108