Warnings of antivirus tools
January 2015 - Antivirus program AVAST
In WinLED from Version 1.2.0 of July 2014, the antivirus program AVAST raises a virus alert called "Win32: Evo-gen [susp]" since December 2014 and deletes WinLED from the hard disk.
This is a so-called "False Positive" => a false alarm of the antivirus program. AVAST itself even stated that only "suspicions" that may indicate a virus is referred to collectively as "Win32: Evo-gen [susp]", but the affected program will be deleted as if a virus has already been found. After searching in the Internet, the problem appears to be widespread and there are complaints about the fact that AVAST has been paralyzed in this way many harmless programs. Unfortunately an attempt to contact AVAST was unsuccessful.
WinLED does not contain malware of any kind if the tool has been downloaded from my blog. In addition, I had once again recompiled WinLED: Fortunately AVAST no longer is raising the virus alert above.
Who got an AVAST false alarm with respect to WinLED should download and install the version from 1.2.2 here from my blog. The same also applies to any other type of real virus alerts. The download of WinLED is legal possible only on my blog, but in the Internet, there are also numerous illegal download offers of WinLED and among them I found downloads, was where WinLED does not contain or was infected with malware.
Januay 2016 - Antivirus program BitDefender
Meanwhile, I have got new feedback, therefore this time the antivirus program BitDefender will report a "False Positives" for the current version WinLED 1.3.2. That's why I had WinLED analyzed at virustotal.com. virustotal.com currently uses 53 different antivirus solutions (including BitDefender) to analyze a file for malware and the analysis of WinLED on virustotal.com found 0 of 53 possible matches. If you want to convince yourself, please follow this link directly in order to review the scan results for WinLED 1.3.2: http://www.virustotal.com/winled
January 2018 - Antivirus program Norton Security
According to a loyal user of WinLED, this time anounced by the Norton Security antivirus program seems to end up adding a Trojan to the WinLED tool. In the current version WinLED 1.5.0 Norton Security claims to have found a Trojan called "Heur.AdvML.B". I then did an updated search on virustotal.com, where WinLED was examined by search engines from more than 60 antivirus solutions, including the manufacturer of Norton Security - Symantec Corp. - who does not want to have found any malware in WinLED.
July 2019 - Antivirus engine VBA32
Again, I've been alerted by loyal users of WinLED that an antivirus engine, this time "VBA32" reports a "False Positive" called "CIL.StupidCryptor.Heur" from multiple WinLED components (including the installer) in all versions. All this engine has discovered: WinLED uses obfuscation tools to prevent hackers from decompiling and modifying the WinLED program code. This should not be a reason for a virus alert and so see it then the other 66 antivirus engines on virustotal.com.
September 2019 - Windows Defender
Since the beginning of September, the Windows 10 Defender discovers a Trojan called "Win32/Fuery.B!Cl" and blocks WinLED. Therefore, as a developer, I had repeatedly contacted Microsoft support and said that WinLED in the version I signed did not contain any malware. Each time a Microsoft Analyst analyzed the incident with the following result:
We have removed the detection. Please follow the steps below to clear cached detection and obtain the latest malware definitions.
1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender 2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures” 3. Run "MpCmdRun.exe -SignatureUpdate"
Alternatively, the latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions
Thank you for contacting Microsoft.
While this is nice to confirm that WinLED does not contain malware, but:
- Unfortunately, the Windows Defender malware detection update guide is aborted with an error message.
- After a normal Windows Defender upgrade, WinLED will be temporarily accepted but will be blocked again after a Windows restart.
Recently, a Microsoft analyst confirmed that WinLED does not contain any malware and Microsoft just can not explain why the Windows Defender wants to detect a Trojan in my Windows 10 system:
The file is not malware and we cannot reproduce any detection on the file. If detection is still observed, please follow the steps below to capture support log files from the system reporting detection.
On Windows 10, from elevated command prompt, change to directory "%programfiles%\windows defender" and execute mpcmdrun.exe with option GetFiles: cd "%programfiles%\windows defender" mpcmdrun.exe -GetFiles
On Windows 7, from elevated command prompt, change to directory "%programfiles%\microsoft security client" and execute mpcmdrun.exe with option GetFiles: cd "%programfiles%\microsoft security client" mpcmdrun.exe -GetFiles
All created log files will be compressed into MPSupportFiles.cab. Please send us the detected file and MPSupportFiles.cab via our web portal https://aka.ms/wdsi (select Submissions/Submit a file). We will continue the investigation once we receive the support log files.
Thank you for contacting Microsoft.
Unfortunately, I can not do anything myself, because I can not remove nonexistent malware from my programs. If you want to support me, follow the instructions of Microsoft on your system and please also report your result to Microsoft. Please make sure, that the "Submit File" is WinLED.exe. The MPSupportFiles.cab I had last always made available in the public area of my OneDrive.
I will not make any further attempts to troubleshoot Microsoft and have now approved the alleged threat of WinLED in my Windows Defender. Who wants to continue to use WinLED will probably have to live with it. If you want to do that as well, please note that I signed WinLED with my name and therefore only the version of WinLED should be used signed by me.
October 2019 - Windows Defender
Since the beginning of October, WinLED has also been detected as malware called "Win32/Unwaders.A!ml" by Windows Defender of Windows 10. However, the signed version of WinLED does not contain any malware. Again, only the configuration of WinLED in Windows 10 Defender as a permissable threat.
|
Comments
WinLED
Do you support Windows 8.1 ?
hiro
http://all-freesoft.net/
The best option is to place WinLed in the top left side of the screen.
Depending on your OS version, you should be able to drag the icon to the notification area to make it stay there, or choose "always show".
thank you matthias! winLED is the best and the latest version works perfectly with latest windows 10!
This application is very useful. My DELL Latitude 3550 not have hdd attention led. It is solve this deficiency, and working well on windows 10 pro x64 default configuration.
But I found a bug.
I have another problem in my laptop. This page review my other problem and provide me the solution: http://moretags.[censored].hu/2015/08/windows-10-blurry-text-fuzzy-font-and-solutions.html
And the bug is: after I run this commands:
REG ADD "HKCU\Control Panel\Desktop" /v DpiScalingVer /t REG_DWORD /d 0x00001018 /f
REG ADD "HKCU\Control Panel\Desktop" /v Win8DpiScaling /t REG_DWORD /d 0x00000001 /f
REG ADD "HKCU\Control Panel\Desktop" /v LogPixels /t REG_DWORD /d 0x00000078 /f
The winled is not working more.
REG ADD "HKCU\Control Panel\Desktop" /v DpiScalingVer /t REG_DWORD /d 0x00001000 /f
REG ADD "HKCU\Control Panel\Desktop" /v Win8DpiScaling /t REG_DWORD /d 0x00000000 /f
REG ADD "HKCU\Control Panel\Desktop" /v LogPixels /t REG_DWORD /d 0x00000078 /f
and I restart my notebook, WinLED application working well again.
Any other information need, write me, ask me.
Big thanks for your work in this projekt.
Thanks a lot for the tip, Stephen.
Now the latest update of WinLED will work well.
Very BIG thanks for rapid bugfix!!
Good day, all the best!!
Who has a problems with the display of WinLED, should look into the application log of the event history of Windows.
If there occur error events to WinLED, please sends it to me so I can identify and fix the error.
Thanks and best regards
Matthias
I suspect inferior antivirus tools as a cause that WinLED does not appear on some computers.
Winled works perfectly well on all the other PCs where Winled were installed a couple months ago.
Contrary, I plan to remove the features for enable/disable individual drives. Since the introduction of this feature I get messages that WinLED has no more function. It seems the Windows Performance Counter for individual drives do not work as desired.
#2- Will the one I downloaded today work on my Win10 64bit computer?
#3- If I wanted to delete after install would it be easy to do?
WinLED is available to download only on my blog. If you downloaded WinLED here, you use the latest version.
Quoting bobz:
Yes. The current version of WinLED works well on my Win10 64bit computer.
Quoting bobz:
Please do not delete WinLED just like that. You can use the Installer as Uninstaller and uninstall so easily WinLED.
Thank you very much for your error report.
Now the WinLED version 1.3.4.3 can be downloaded here, which can be installed on cultures other than English and German.
Details: Cannot load Counter Name data because an invalid index " was read form the registry.
WinLED now exits.
Any help appreciated. version 1.4
After I got the feedback that WinLED users can not open the WinLED contextmenu, I had looked for the problem and published a new version of WinLED on my blog.
The context menu should now be able to be opened again as usual.
The problem has only occurred with users who have more than one drive. If you have only one drive in your computer, neither you will discover a change in WinLED nor will you need this new version.
is there any way to manually uninstall winled fully because I have some remaining files from an older version (also still shows up in config program - Add/remove programs) but it doesn't work.
When I try to uninstall or reinstall by using the latest version it always comes up with an error and nothing changes.. Any thoughts?
That's not the case!
The details are described in the section "Warnings of Anti-Virus Tools" in this article.
Is it possible to write precisely on your blog the current version of WinLED as well as the changelog please?
On softpedia, this is version 1.5.3.3 and I don't see a specific version number on your blog