Important Notice: On February 29th, this community was put into read-only mode. All existing posts will remain but customers are unable to add new posts or comment on existing. Please feel to join our Community Discord for any questions and discussions.

Unwanted software in Package Library

What a great thing to have a package library.

Using PDQ-deploy, you gain the benefit of having an all time fully updated machine park in your network, getting rid of ASK toolbars, McAfee offers and such.

But... from time to time, I find software in the PDQ Package Library that contains software that to me are questionable. Like I have been write before, some of the packages are listed as suspicious when scanned through antivrus scanners. Right now for instance... try to run PDF-creator (PDFCreator-2_0_1-setup.exe) through virustotal.com

Reading PDFforge website it also seems that they have introduced som ad-ware in their PDF-creator from version 2.0.

My point is that it would be desirable that the Package Library is 100% trustable. If some kind of malware is uploaded to the Package Library, it would be nice to have this software marked as suspicious in some way. So that an admin would be notified to evaluate the package further.

Naturally, I do expect that no direct virus or other strong harmful malware are placed in the Package Library. But in case a package are in a grey area, a specific notification would be desirable.

Regards, Lars.

0

Comments

1 comment
Date Votes
  • Hi Lars,

    We run all of our packages through Anti-Virus to ensure that no malware or viruses exist and are transferred to our customers.  I have seen instances of malware being caught on packages because the vendors include things like OpenCandy in their installation files, but we use the proper silent parameters so this doesn't get installed or affect your targets although we can't strip this out of the vendor's software.

    Jason 

    0