TrafficMonitor icon indicating copy to clipboard operation
TrafficMonitor copied to clipboard

TrafficMonitor.sys is identified as Trojan:Win32/Vigorf.A by Windows Security

Open abhi-deshpande opened this issue 3 months ago • 17 comments

Prerequisites

  • [x] I have searched for related issues in the issues list.
  • [x] I have read the FAQ in detail and searched for related issues in FAQ list.

Current TrafficMonitor Version

1.85.1 (x64)

Current Operating System Version

Windows 11 Pro 24H2 26100.4946

What happened?

After a recent Security Intelligence Update for Microsoft Defender Antivirus, the TrafficMonitor.sys file is identified as Trojan:Win32/Vigorf.A by WIndows Security. This seems to be a false positive, but I am not sure why it is happening.

Image

Log Output


Additional Information

No response

abhi-deshpande avatar Sep 05 '25 16:09 abhi-deshpande

I was about to report the same thing.

m-a-hannan avatar Sep 06 '25 01:09 m-a-hannan

Image

Experiencing the same issue

Touhid0101 avatar Sep 06 '25 04:09 Touhid0101

i got the same Trojan. from same ver. 1.85.1 (x64) 26100.4946

Image

khaledsallam14 avatar Sep 06 '25 04:09 khaledsallam14

same here.. Im worried that this isnt safe to use but according to virustotal it seems like its false positive..

Image

Inemene avatar Sep 06 '25 12:09 Inemene

I just tried to search more about this threat and found that it really has to do with latest virus definitions for Windows Security. This issue is affecting a lot of legitimate apps.

See here: https://github.com/LibreHardwareMonitor/LibreHardwareMonitor/issues/1844

This project also uses core components from LibreHardwareMonitor.

abhi-deshpande avatar Sep 06 '25 12:09 abhi-deshpande

There is a new method to solve this problem. https://github.com/zhongyang219/TrafficMonitor/issues/2164#issuecomment-3310561714 I replaced the file "LibreHardwareMonitorLib.dll" in the "TrafficMonitor" folder with the one from the "LibreHardwareMonitor nightly build", and it solved the issue temporarily. The steps are as follows: 1. Go to the URL "https://github.com/LibreHardwareMonitor/LibreHardwareMonitor". 2. Download the nightly build zip. 3. Verify that TrafficMonitor.exe has been closed. 4. Extract "LibreHardwareMonitorLib.dll" from the nightly build zip, then copy and replace it in the "TrafficMonitor" folder. 5. Restart "TrafficMonitor.exe".

gnc-gh avatar Sep 07 '25 06:09 gnc-gh

I replaced the file "LibreHardwareMonitorLib.dll" in the "TrafficMonitor" folder with the one from the "LibreHardwareMonitor nightly build", and it solved the issue temporarily.

The steps are as follows: 1. Go to the URL "https://github.com/LibreHardwareMonitor/LibreHardwareMonitor". 2. Download the nightly build zip. Image 3. Verify that TrafficMonitor.exe has been closed. 4. Extract "LibreHardwareMonitorLib.dll" from the nightly build zip, then copy and replace it in the "TrafficMonitor" folder. 5. Restart "TrafficMonitor.exe".

This is did not help. It still throws a lot of security threats.

Image

KertLynx avatar Sep 19 '25 03:09 KertLynx

I replaced the file "LibreHardwareMonitorLib.dll" in the "TrafficMonitor" folder with the one from the "LibreHardwareMonitor nightly build", and it solved the issue temporarily. The steps are as follows: 1. Go to the URL "https://github.com/LibreHardwareMonitor/LibreHardwareMonitor". 2. Download the nightly build zip. Image 3. Verify that TrafficMonitor.exe has been closed. 4. Extract "LibreHardwareMonitorLib.dll" from the nightly build zip, then copy and replace it in the "TrafficMonitor" folder. 5. Restart "TrafficMonitor.exe".

This is did not help. It still throws a lot of security threats.

Image

https://github.com/zhongyang219/TrafficMonitor/issues/2164#issuecomment-3310561714

gnc-gh avatar Sep 19 '25 05:09 gnc-gh

Image

MW11W avatar Sep 19 '25 09:09 MW11W

Wait Developor use this LibreHardwareMonitor and update it

tony8077616 avatar Sep 20 '25 04:09 tony8077616

https://bbs.kafan.cn/thread-2278851-1-1.html https://bbs.kafan.cn/thread-2285111-1-1.html

#2151

Bedingled403 avatar Sep 28 '25 05:09 Bedingled403

Image

KertLynx avatar Oct 06 '25 03:10 KertLynx

This application is dangerous and can hard your hard drives. I had to remove it and run an antivirus scan just to be safe. I have reported this to Github as malware. I'd suggest everyone to also add your comments at https://hellogithub.com/en/repository/5ef48af2b2794d4798b17d6539ec7305 to let userbase know to stay away from this malware.

KertLynx avatar Oct 06 '25 03:10 KertLynx

Image

same here

ZeroSnake00 avatar Oct 06 '25 15:10 ZeroSnake00

This application is dangerous and can hard your hard drives. I had to remove it and run an antivirus scan just to be safe. I have reported this to Github as malware. I'd suggest everyone to also add your comments at https://hellogithub.com/en/repository/5ef48af2b2794d4798b17d6539ec7305 to let userbase know to stay away from this malware.

Now, here's something I'm going to ask you....have you experienced ANY hardware issues, or ANYTHING other than Windows Defender screeching its head off about a "Virus" on your system before, during, and after using it? I most certainly haven't, and I'm still using it without even getting a virus pop-up.

ZeroFighter17 avatar Oct 12 '25 23:10 ZeroFighter17

This application is dangerous and can hard your hard drives. I had to remove it and run an antivirus scan just to be safe. I have reported this to Github as malware. I'd suggest everyone to also add your comments at https://hellogithub.com/en/repository/5ef48af2b2794d4798b17d6539ec7305 to let userbase know to stay away from this malware.

Now, here's something I'm going to ask you....have you experienced ANY hardware issues, or ANYTHING other than Windows Defender screeching its head off about a "Virus" on your system before, during, and after using it? I most certainly haven't, and I'm still using it without even getting a virus pop-up.

I would rather trust dozens of security alerts posted by many here than one person like you saying its harmless.

KertLynx avatar Oct 17 '25 08:10 KertLynx

Based on the suggestion on this thread https://github.com/zhongyang219/TrafficMonitor/issues/2164#issuecomment-3458112599, I downloaded the latest nightly build from here: https://nightly.link/LibreHardwareMonitor/LibreHardwareMonitor/workflows/master/master/LibreHardwareMonitor.zip and copied LibreHardwareMonitorLib.dll and nothing else. Didn't even install PawnIO and it seems to work. So far no security alerts!

KertLynx avatar Oct 29 '25 03:10 KertLynx