Hi @twgiu I just downloaded the 32-bit version of Notepad++ from the official website (https://notepad-plus-plus.org/downloads/v7.9.1/) and sent notepad++.exe to virustotal. One of the 72 engines detected malware (Trojan.Generic.giteg). I also uploaded the 64-bit version and it was clean.
Being only one engine, named Jiangmin, that detected the virus I’d would be inclined to say that it is a false positive. If possible you can test the 64-bit version and if it results clean, then use that version?
For peace of mind you can also post an issue in github (https://github.com/notepad-plus-plus/notepad-plus-plus) where notepad++ developers could confirm whether the downloads are legit or not.