Flagged as malware on VirusTotal

All recent versions of Joplin Portable (for Windows) are flagged as malware by at least one security vendor on VirusTotal (for instance, v3.0.14).

Is there anything we can do about that?

It is worth noting that this keeps happening even several versions later (v3.1.24).

The same problem happens for all versions in between; if you are interested, I can post their links here (I just wanted to avoid spamming the forum with too many links).

This is not a bug in Joplin but in the virus scanner so that's where it should be reported. The more it's being reported, the more likely the vendor will fix their virus signature database.

I completely agree that it is not a bug in Joplin.
I have already reported it a few times, and I will continue to do so. I hope others will do the same :wink:

I wrote here just to point out this issue so that if someone knows how to "tweak" the code for Windows to prevent this problem (I don't know if it exists), we could avoid that in the future.

A quick update on this.
Unfortunately, it continues to occur even in the latest version v3.2.13.

In the "Dropped Files" section of the Relations tab you can see a single file with one detection:

1/72
Win32 DLL
node_sqlite3.node
SHA-256: 7fb52b781709b065c240b6b81394be6e72e53fe11d7c8e0f7b49dd417eb78a01

I am unsure whether this can help to identify/resolve the potential issue; hopefully someone with more expertise can assist.

For reference, I'm linking to the node SQLite3 GitHub project:

Update

Also the latest version (3.3.13) is flagged as malicious by 1/56 security vendor:

VirusTotal - File - fc5f5a6cb17aac3e7947e654f344c7c08c6fdfcc3767356a09f1cc5ba384565a

The compressed files have 0 detections, and none of the “Bundled Files” have been detected as malicious this time.

What exactly do you mean by “Flagged by Virus total?” Virus total submits a fingerprint to roughly 80 different antivirus programs. Virus total does not flag anything. Out of these 80 different programs, Virus total normally gets a response from roughly 77. The others time out. Out of those 77, which ones presented the false positive on this program? Was it ANY of the normal respected anti-virus programs? My guess is not.

As a comparison, All Fujitsu scanners get 1 or 2 reports of being malware. Brother printer drivers are normally picked up by 1 or 2. Chaos Software’s Intellect alarm is tagged by 3 of 78.

Keepass by 1 of 77

Carthago’s Meminfo by 2 of 77

Temp Cleaner by sordum.org by 1 of 77

Asus motherboards have a driver tagged by 1 of 77

IDrive backup service by 1 of 77

These are just the ones currently running in the background on my system.

In general, if less than 5 of the 80 report the positive result, don’t worry about it, because it means about 75 think it is ok.

Hi,

I just looked at the info and virus total and it doesn't look like it's malicious it just says may differ from commercial version which is meaningless. And every other entry is normal.

I would also suggest looking at which AV software specifically has actually marked the file as malicious. Not all of them are equal, and many are completely unreliable.

@SteveShank @LeoW @tomasz86 as mentioned in a previous post:

Since we all look to improve and build deeper trust within the users, avoiding false detections, which most legitimate software handles smoothly, will be a huge step forward.


Just so you know, even the most recent version is still being flagged:

So, out of 80 antivirus programs, one obscure one, SecureAge (ever heard of it?), which is known for false positives, gives the PORTABLE version of Joplin, not the standard version, a false positive. You believe someone should work to tweak the code to avoid that, but not cause any other problem. It would make more sense to write Virus Total to get rid of SecureAge so its frequent false positives stops confusing people.