Bitdefender: Infected file deleted

Operating system

Windows

Joplin version

3.0.15

What issue do you have?

I have bitdefender antivirus plus installed on windows 11 machine. I get the following message every time I open joplin:

"The file C:\Users\XXX.config\joplin-desktop\tmp\b21728f37a335a8fba3aa5586f8f132e\08a669877a8345e9858aa91a5c26d8d3.md is infected with Heur.BZC.PZQ.Boxter.81.378A8EE6 and was moved to quarantine. It is recommended that you run a System Scan to make sure your system is clean."

Is this a false alarm?

@takisk welcome to the forum.

Likely but it may depend on what you had put in your note stored as 08a669877a8345e9858aa91a5c26d8d3.md. Did your note contain script / code?

https://support.avira.com/hc/en-us/articles/360000819265-What-is-a-HEUR-virus-warning

What is a HEUR virus warning?

Heuristic refers to a "preliminary detection" feature that can also detect unknown viruses. It involves a complex analysis of the affected code and scanning for virus-specific functions. If the analyzed code does meet such characteristics, it is reported as suspect.

This does not mean, however, that the code is a virus for sure; false positives may occur.

Thanks for the reply. How do I find specific note?

I am not familiar with BitDefender, but look in its quarantine store?

Locate and open the file above in file explorer, or another solution:

in any note, add [click me](:/08a669877a8345e9858aa91a5c26d8d3) and follow the link

The [click me] worked. Found a pentest note referring to bloodhound that apparently the AV did not like.

Thanks for the help!

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.