Jump to content

Expert System Algorithms FP Malware.Heuristic.1003 of QuarkXPress 2021


Recommended Posts

After installing the new QuarkXPress 2021 (version 17.0.0), with Use Expert System Algorithms enabled, scans now yield a false positive of Malware.Heuristic.1003 for C:\PROGRAMDATA\QUARK\QAUDUMP\QUARK UPDATE.MSI in Malwarebytes 4.4.0 and 4.4.2.


A couple of weeks ago I had a similar issue with Corel Video Studio involving Malware.Heuristic.1001 and Quark's Updater utility being flagged with Malware.Heuristic.1003. After Senior Research Engineer, Rich Matteo, whitelisted those files I uploaded on June 10th, they stopped getting flagged.  I am curious if Quark's anti-piracy measures are engaging in excessive monitoring activity that may be perceived as malicious?



False Positive Malware.Heuristic.1003 for QuarkXPress 2021.zip

Link to post
Share on other sites

  • Staff

These files are just malformed. That is what the heuristic picks up. They are non standard constructed or packed compared to a normal windows executable. 

Its advised to leave the expert system algorithms setting off in malwarebytes. There will be more fps if its left on. It is designed if there is an infection to turn it on to possibly catch zero day malware. 


This file is now whitelisted. 


  • Thanks 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.