Reproducible release evidence

Windows Shortcut Security Lab

This lab publishes the measured release gates behind Shortcut Remover 8.0.0: labeled shortcut behavior, scale and responsiveness, accessibility checks, artifact identity, and a real Windows drive-root scan. Results are reported with their limits so controlled evidence is not mistaken for a universal malware-detection claim.

327 / 327automated release tests passed
910labeled shortcut cases in the controlled corpus
100,000files in the largest controlled scale scenario
17,486files observed in a separate real drive-root scan

Download the evidence CSV Inspect the release manifest

Release identity

Product version
8.0.0
Build ID
8.0.0-rc-1786773149059
Installer SHA-256
5F01CDDCC013DD1CAD3086BA67A5AA0E2C2989774E1854901165CE7760EBB834
Automated tests
327 passed, 0 failed
Code signing
Not Authenticode-signed; verify the published hash before use

Controlled labeled shortcut corpus

The release gate contains 310 labeled malicious cases and 600 labeled benign cases. All 310 malicious cases were detected, and all 600 benign cases remained unselected as malicious. No input file was modified or lost during the 2.024-second corpus run.

Class Labeled Correctly classified Misclassified
Malicious test shortcuts 310 310 true positives 0 false negatives
Benign test shortcuts 600 600 true negatives 0 false positives
Interpretation limit: this is a versioned, controlled regression corpus. It demonstrates expected behavior for the included families; it does not establish perfect detection of unknown, future, corrupted, or environment-dependent threats.

Scale, pause, and cancellation gate

The controlled NTFS gate exercised 1, 1,000, 10,000, and 100,000 input files. Larger scenarios included deterministic 1% access failures and 1% malformed-shortcut parse failures so accounting could be verified.

Measurement Observed value Scope
100,000-file elapsed P95 6,922.418 ms Controlled local NTFS test root
100,000-file throughput P50 16,507.253 files/second Release-test environment, not an end-user promise
Peak working set 71,368,704 bytes Observed across the gate
Cancellation response P95 0.4514 ms Injected-delay harness signaling measurement
Pause progress drift 0 files 800.2884 ms frozen observation window
Residual items 0 No test files, directories, or harness workers left behind

Real drive-root observation

The compiled release candidate performed a separate read-only quick scan of a real D:\ drive root. It completed naturally in 2 minutes 13.774 seconds and reported 42 directories, 17,486 files, 12 shortcuts, two access errors, zero reparse-point skips, and no safety-limit stop.

The two access errors caused an incomplete result and exit code 3. The product did not present the partial coverage as a clean or complete scan. This observation independently reproduced the corrected volume-root behavior; the earlier 25-millisecond, zero-file failure did not recur.

Shortcut Remover scan results with directory, file, shortcut, and coverage counts
Coverage counters and access errors help distinguish a complete scan from a partial one.

Accessibility and product-level checks

  • 48 instrumented product end-to-end checks.
  • 5 removable-drive runtime scan product checks.
  • 60 window scenarios, 1,537 interactive nodes, and 240 screenshots across 10 languages.
  • 0 actionable violations in the automated UI Automation and keyboard gate.

Narrator behavior was not verified in the release environment. Automated accessibility evidence reduces risk but does not replace testing by people who use assistive technology.

Evidence files

Known evidence gaps

  • Unattended physical USB scale testing was deferred; the scale gate used a controlled fixed-disk NTFS root.
  • The real drive-root observation represents one device and one file population.
  • Automated UI checks do not establish complete accessibility for every assistive technology.
  • The installer is currently unsigned and may show an Unknown publisher warning.
  • No static or behavioral shortcut check can guarantee that every referenced remote resource remains safe later.

Download the tested build Inspect one .LNK file locally