# Librewolf's Windows updater is malware?!

**URL:** https://discuss.privacyguides.net/t/librewolfs-windows-updater-is-malware/16447
**Category:** Questions
**Created:** 2024-01-24T19:25:41Z
**Posts:** 14

## Post 1 by @L_ishere670 — 2024-01-24T19:25:41Z

I was updating Librewolf manually on Windows and i found that Librewolf’s updater and i scanned it using Virustotal and [the results](https://www.virustotal.com/gui/file/c2bdd176740c4169abe6733f3fab93cc1991ad36937fa7e571b40f4e9cc431be) were a shock to me as 5 antivirus companies flagged it as a malware, Could anyone explain?

---

## Post 2 by @FlipSid — 2024-01-24T19:28:31Z

First off what is in that link?

---

## Post 3 by @Ganther — 2024-01-24T19:36:58Z

5 antiviruses are presumably trash and need to update their lists.

---

## Post 4 by @exaCORE — 2024-01-24T20:02:13Z

Just use Mullvad browser instead…

---

## Post 5 by @vergeOfNormy — 2024-01-24T20:24:29Z

RIP  
when are windows user going to catch a break?

---

## Post 6 by @Stiffly2505 — 2024-01-24T20:27:40Z

Antiviruses are garbage, this is a pretty normal result for a fresh and unknown binary. The only way to get lower is to sign your binaries.

---

## Post 7 by @anon73250778 — 2024-01-25T15:22:30Z

I looked at this again, now only 4 vendors (from 5) flag it as malware.

Its not that the others are crap, its just that their virus signatures are overtly aggressive and gives a false positive. As @Stiffly2505 puts it the binaries are not signed (you may get the signing keys from MSFT :rofl: I dont know what they would want).

You were not the first one that submitted this particular file @L_ishere670 . Someone beat you a whole day before.

There were the IP addresses that were contacted by the updater (according to the VT details) and the first 3 in the list were flagged and was associated with certain malwares. It could be something or nothing all together.

---

## Post 8 by @Stiffly2505 — 2024-01-25T15:36:06Z

> you may get the signing keys from MSFT :rofl: I dont know what they would want

Incorrect, you can just buy a code signing certificate from any trusted partner: [List of Participants - Microsoft Trusted Root Program | Microsoft Learn](https://learn.microsoft.com/en-us/security/trusted-root/participants-list)

its not even _that_ expensive, about 150 USD/year for the cheap ones. And Certum has an even cheaper OSS one, too bad they suck as a CA.

---

## Post 9 by @Sprout3425 — 2024-01-26T11:49:22Z

Correct me if I am wrong, but to me it seems that antiviruses themselves are the malware. If you are using Windows or Apple’s OSs they come with antiviruses by default. Also, you have 5 of them!?

---

## Post 10 by @user1 — 2024-01-26T12:13:07Z

He doesn’t have 5 antivirus installed, he’s using [virustotal.com](http://virustotal.com)

---

## Post 12 by @Average_Joe — 2024-09-24T21:01:10Z

> [@user1](#):
>
> He doesn’t have 5 antivirus installed, he’s using [virustotal.com](http://virustotal.com)

Is [virustotal.com](http://virustotal.com) considered the best online virus scanner which doesn’t require the antivirus to be installed on your device?

---

## Post 13 by @quettaflare — 2024-09-25T03:45:21Z

I think its more a mix of convenience of no install required to scan a file, and more well-known in terms of online virus scanners (or at least that I’m personally aware of).

---

## Post 14 by @Average_Joe — 2024-11-04T13:53:54Z

> [@quettaflare](#):
>
> I think its more a mix of convenience of no install required to scan a file

I appreciate your reply!

I’ve always been interested in “portable apps”, especially on the Windows side of things. It seems nice to be able to just have your apps running off an encrytped USB drive.

**However, everyone should be careful of “portable apps” that come from unofficial websites and are often spyware.**
