QSpice: Scanning results from VirusTotal

Greetings,

QSPICE is a powerful tool no doubt about it, but honestly a lot of files are infected (mostly the compiled ones with Digital Mars compiler).

I dig deeper and I downloaded the same compiler version and boom!, almost all the exe files are infected, I don’t know if the development team aware of that ?! was it intentional ?

be1f7844b1a821bb8d1e793e9c26be0363499301468ee44b122b440f40658443
b0abdf00c8215ed3742dbea84342579b946cd6e3870519c41f5fb131d9d210e1
6ddf4d7a882e61874db8bccad951e5a3592c7349d5ab952adb64e0b4cc9ff762
1902053e30b831da8cf064937625b38db65317bf2839a9a277ad897b214101a6

fb5691ae694248cbf958e6310bf8b3efcda18b98f28c44fc4c56fe8570e23cdb

e8e830e6676f6c8bd83ffe0a9a3dc8b9f8952f96e54a839017ee14f0f5426231

76ce97680a795293158d85d88a2368f98beadc4f7da6ffc51103e4694f9dcc30

9c1b6c24643c098980d2180e623c36df55663b2cbf572f71cfbb7ff43af1d906

bf7ccd8e9e17d760430ebd0ca2d5f98bf7b2c96572d03b0540915c4f48c9f2f5

examples dll:
636eb0e7501c12d4c36afd274e60f57fbfc9d6f4fe9bf459034a0e8981ca63a2

7583d3738bdfebf975825c033d76a92e2403ee9822823b6b7ec8a3f6cd952b0b

e6b7e67650d465e6c96d13c0a71de759038346169033e3ba09855694d5be591b

this too much to be a false positive, why are you not using gcc or clang ? serious question.

B. Regard,
xjag

This is unofficial, and a formal reply should come from the Qorvo team.

But things for you to consider

  1. This is a post from 2023 by Mike Engelhardt, the author of QSpice, talking about antivirus software.
    MALWARE Detection - Type: TROJAN, Detection Name: ARTEMIS!Cxxxxx. I can no longer use QSPICE under this circumstance - QSPICE - Qorvo Tech Forum
  2. This is my scan result from Microsoft Defender
1 Like

I saw the old threads, but to be honest something is odd with this Mars Compiler binaries. as I mentioned it needs really to be considered/checked, either compiling MDC from source code or move to another compiler.
I have a strong feeling that something is not right, too much red flags to be considered as a false positive.

Hello xjag

You may want to scan your computer: if you have that many infected (and they turn out to be true, not false positives), it may indicate that they were infected by something else, in turn. Also, use more than one AV, if you can.

Vlad

1 Like

Hello archbugaboo,

thanks for the feedback, I have fresh VM but still lot of files are infected, maybe we need the feedback from core developers here.

xjag

I use QSpice almost daily since it launched in 2013; and if it contains malware, I should have been in trouble a very long time ago. QSpice can compile and run DLLs, which is a common cause for false positives. I zipped the QSpice folder and uploaded it to VirusTotal. The so-called Detection for the Digital Mars C++ Compiler in the dm directory is only 1 to 3 out of about 70 security vendors.

VirusTotal is crowd-sourced malware scanning, whitelist a file requires submit a false-positive report directly to the specific antivirus company. For Qspice: Microsoft, AVG, CrowdStrike, Kaspersky, McAfee etc… all reported Undetected in VirusTotal.

The QSpice forum is currently more of a community-based crowd-support platform.
For official support, refer to QSpice > Help > About QSpice for email contact.

1 Like

I have updated the post title from Qspice is a hive of malwares to QSpice: Scanning results from VirusTotal to keep the topic objective and neutral.

1 Like

I am not gonna tell where I work, but it’s allowed to be used at my work where it’s regirously tested before being allowed to be installed… So I doubt it has any infection. IDE Arduino is on the other hand not allowed at my work… Due to security issues. Hopes this helps you

Hi all,

This morning, I had the same issue as xjag.
I am using ESET Internet Security (Japanese version).

It may be related to an update of ESET rather than a QSPICE update.
Has anyone else seen the same issue?

Today my ESET Antyvirus kill all files exe from QSPICE directory and when I was trying to update, a update file was deleted too, like a virus.


Hi

I updated ESET today and restored the QSPICE files from the ESET quarantine folder.
ESET scanned these files, and no suspicious files were found.

This confirms that the detection was a false positive.

@KSKelvin Thank you for your advice. I have sent these files from the ESET quarantine folder to ESET support.

1 Like