<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Notepad++ 32bit installer detected as malware on virustotal?]]></title><description><![CDATA[<p dir="auto">Went to check the installer like I normally for anything I download noticed the 32bit installer detected 5/50. I’m sure these are false positives, but I’d thought I’d post here to let the developers know incase they don’t.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/17247/notepad-32bit-installer-detected-as-malware-on-virustotal</link><generator>RSS for Node</generator><lastBuildDate>Sat, 11 Jul 2026 23:58:34 GMT</lastBuildDate><atom:link href="https://community.notepad-plus-plus.org/topic/17247.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 Mar 2019 16:31:57 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Fri, 08 Mar 2019 14:02:30 GMT]]></title><description><![CDATA[<p dir="auto">looking at bkav’s <code>HW32.Packed</code> detection, it might indicate, that it is triggered by the nsis compressor setting<br />
<code>SetCompressor /SOLID lzma</code> in <code>nppSetup.nsi</code>, as the result is an .exe with compressed resources.</p>
<p dir="auto">just like .exe files, that are compressed with UPX.<br />
they often (as in very, very, very often) produce heuristic virus alerts.</p>
<p dir="auto">and now, with the missing code signing certificate, it might be possible, that the engines do not whitelist the notepad++ installer any more, if they have whitelisted it before.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40821</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40821</guid><dc:creator><![CDATA[Meta Chuh]]></dc:creator><pubDate>Fri, 08 Mar 2019 14:02:30 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Fri, 08 Mar 2019 12:41:52 GMT]]></title><description><![CDATA[<p dir="auto">If you unpack the installer all clean!<br />
I think it was found in the installer script, or maybe I’m wrong.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40820</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40820</guid><dc:creator><![CDATA[andrecool-68]]></dc:creator><pubDate>Fri, 08 Mar 2019 12:41:52 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Fri, 08 Mar 2019 07:06:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/meta-chuh" aria-label="Profile: Meta-Chuh">@<bdi>Meta-Chuh</bdi></a> yeah URL is fine the file has some detections.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40813</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40813</guid><dc:creator><![CDATA[Chowder908]]></dc:creator><pubDate>Fri, 08 Mar 2019 07:06:57 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Fri, 08 Mar 2019 00:18:30 GMT]]></title><description><![CDATA[<p dir="auto">hi <a class="plugin-mentions-user plugin-mentions-a" href="/user/andrecool-68" aria-label="Profile: andrecool-68">@<bdi>andrecool-68</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/user/chowder908" aria-label="Profile: Chowder908">@<bdi>Chowder908</bdi></a> and all</p>
<p dir="auto">i can confirm, that a <a href="http://virustotal.com" rel="nofollow ugc">virustotal.com</a> <strong>url scan</strong> shows no virus detections, but if i download the npp installer from the same url, and manually <strong>upload</strong> it to <a href="http://virustotal.com" rel="nofollow ugc">virustotal.com</a>, it will trigger some virus/malware detections.</p>
<hr />
<p dir="auto"><strong>url scans:</strong></p>
<p dir="auto">url: <code>https://notepad-plus-plus.org/repository/7.x/7.6.4/npp.7.6.4.Installer.exe</code><br />
result: <a href="https://www.virustotal.com/#/url/06f2b4b05f83ff97b63c0c8f009b8d1698260d065fefee62b3d2af66877d0852/detection" rel="nofollow ugc">https://www.virustotal.com/#/url/06f2b4b05f83ff97b63c0c8f009b8d1698260d065fefee62b3d2af66877d0852/detection</a><br />
sha: 3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157<br />
<strong>detections: 0/69</strong></p>
<p dir="auto">url: <code>https://notepad-plus-plus.org/repository/7.x/7.6.4/npp.7.6.4.Installer.x64.exe</code><br />
result: <a href="https://www.virustotal.com/#/url/0a2390eae8713b5ff96d97cc3107b54c4a188117da626d0cb65beb8c68fc675e/detection" rel="nofollow ugc">https://www.virustotal.com/#/url/0a2390eae8713b5ff96d97cc3107b54c4a188117da626d0cb65beb8c68fc675e/detection</a><br />
sha: 2716fbb5180e2fd7264c4c2f5c74f280d355cbdb9660c6b7d18bc506f7b87398<br />
<strong>detections: 0/69</strong></p>
<hr />
<p dir="auto"><strong>file scans, manually uploaded to <a href="http://virustotal.com" rel="nofollow ugc">virustotal.com</a></strong>:</p>
<p dir="auto">file: <code>npp.7.6.4.Installer.exe</code><br />
result: <a href="https://www.virustotal.com/#/file/3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157/detection" rel="nofollow ugc">https://www.virustotal.com/#/file/3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157/detection</a><br />
<strong>detections: 4/68</strong></p>
<p dir="auto">file: <code>npp.7.6.4.Installer.x64.exe</code><br />
result: <a href="https://www.virustotal.com/#/file/2716fbb5180e2fd7264c4c2f5c74f280d355cbdb9660c6b7d18bc506f7b87398/detection" rel="nofollow ugc">https://www.virustotal.com/#/file/2716fbb5180e2fd7264c4c2f5c74f280d355cbdb9660c6b7d18bc506f7b87398/detection</a><br />
<strong>detections: 2/68</strong></p>
<hr />
<p dir="auto">can anybody else confirm that too ?<br />
or has anybody discovered a plausible explanation for that ?</p>
<p dir="auto">it is very intriguing, as i don’t recall any <a href="http://virustotal.com" rel="nofollow ugc">virustotal.com</a> tests, where an url scan result has differed from an upload result of the same file, producing the false positives we currently see.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40811</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40811</guid><dc:creator><![CDATA[Meta Chuh]]></dc:creator><pubDate>Fri, 08 Mar 2019 00:18:30 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Thu, 07 Mar 2019 18:37:57 GMT]]></title><description><![CDATA[<p dir="auto">Yeah I was just about to post that I looked at the wrong sha256. Looked at the 64bit one not 32. Tho this is a little suspicious since the 64bit installer only has a 1/70 detection. Still it’s most likely a false positive.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40801</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40801</guid><dc:creator><![CDATA[Chowder908]]></dc:creator><pubDate>Thu, 07 Mar 2019 18:37:57 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Thu, 07 Mar 2019 18:27:28 GMT]]></title><description><![CDATA[<p dir="auto">Everything matches!<br />
<a href="https://notepad-plus-plus.org/repository/7.x/7.6.4/npp.7.6.4.sha1.md5.digest.txt" rel="nofollow ugc">https://notepad-plus-plus.org/repository/7.x/7.6.4/npp.7.6.4.sha1.md5.digest.txt</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/40800</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40800</guid><dc:creator><![CDATA[andrecool-68]]></dc:creator><pubDate>Thu, 07 Mar 2019 18:27:28 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Thu, 07 Mar 2019 17:56:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/andrecool-68" aria-label="Profile: andrecool-68">@<bdi>andrecool-68</bdi></a> the SHA256 don’t match with the download link on the download page.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40797</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40797</guid><dc:creator><![CDATA[Chowder908]]></dc:creator><pubDate>Thu, 07 Mar 2019 17:56:40 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Thu, 07 Mar 2019 17:21:15 GMT]]></title><description><![CDATA[<p dir="auto">The first time I checked the link to the file, and now checked the downloaded file. You are right to show that there is a virus.<br />
<a href="https://www.virustotal.com/ru/file/3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157/analysis/1551978217/" rel="nofollow ugc">https://www.virustotal.com/ru/file/3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157/analysis/1551978217/</a></p>
<p dir="auto">SHA256:	3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157<br />
File name:	npp.7.6.4.Installer.exe<br />
Detection ratio:	4 / 70<br />
Analysis date:	2019-03-07 17:03:37 UTC ( 4 minutes ago ) View latest</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40794</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40794</guid><dc:creator><![CDATA[andrecool-68]]></dc:creator><pubDate>Thu, 07 Mar 2019 17:21:15 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Thu, 07 Mar 2019 16:53:03 GMT]]></title><description><![CDATA[<p dir="auto">I used <a href="https://www.virustotal.com/#/file/3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157/detection" rel="nofollow ugc">https://www.virustotal.com/#/file/3e95ce4191b73c755a3139c4df5039b255069eadda57ae827cbf843c60836157/detection</a><br />
Looks like it dropped from 5 to 4 so I guess it’s a false positive.</p>
]]></description><link>https://community.notepad-plus-plus.org/post/40791</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40791</guid><dc:creator><![CDATA[Chowder908]]></dc:creator><pubDate>Thu, 07 Mar 2019 16:53:03 GMT</pubDate></item><item><title><![CDATA[Reply to Notepad++ 32bit installer detected as malware on virustotal? on Thu, 07 Mar 2019 16:41:07 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://www.virustotal.com/ru/url/06f2b4b05f83ff97b63c0c8f009b8d1698260d065fefee62b3d2af66877d0852/analysis/1551976063/" rel="nofollow ugc">https://www.virustotal.com/ru/url/06f2b4b05f83ff97b63c0c8f009b8d1698260d065fefee62b3d2af66877d0852/analysis/1551976063/</a></p>
]]></description><link>https://community.notepad-plus-plus.org/post/40790</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/post/40790</guid><dc:creator><![CDATA[andrecool-68]]></dc:creator><pubDate>Thu, 07 Mar 2019 16:41:07 GMT</pubDate></item></channel></rss>