Why Windows identifies random apps as threats

Some Windows PC owners woke up earlier this week to find their computers suddenly receiving spam messages from Windows Defender warning them about a new “HackTool” called WinRing0. While these warnings are certainly concerning, chances are your computer isn’t actually under attack—at least not yet. But that doesn’t mean you should ignore the warnings.

Why WinRing0 started activating Windows Defender

The problem with random alerts like this is that it's not always clear what the threat is or why Defender considers it a threat. In the case of WinRing0, it's because an exploit in that kernel-level software has previously been linked to dangerous malware (as BleepingComputer reported).

Having kernel-level access essentially means that WinRing0 has access to core components and resources of the operating system. That's a dangerous gamble if the software can be exploited in some way, and it appears that WinRing0 has become the primary driver behind how the SteelFox malware operates and gains access to infected systems.

Even if you've taken the effort to harden your Windows PC's security with Defender, malware like SteelFox can still use the vulnerability found in WinRing0 to bypass your protections.

Another big problem with software like WinRing0 is that it tends to find its way into a lot of different software. That’s the case with this latest Windows Defender warning, which The Verge reports is part of a number of widely used PC fan control apps, including Fan Control, which was mentioned a few years ago.

Windows Defender also seems to trigger the warning if you have other third-party monitoring software installed, including Libre Hardware Monitor, MSI Afterburner , SteelSeries Engine, Razer Synapse, OmenMon, etc.

This is not surprising.

The overall impact of this on monitoring software like Afterburner and Fan Control is clear. Unless Microsoft provides some way for these apps to access these low-level permissions in the future, you’re taking a huge security risk by installing and using any of them.

The move isn’t entirely unexpected, however. Last year’s massive CrowdStrike breach had dire consequences for many companies, including some in the healthcare industry. Since then, Microsoft has been under a lot of pressure to close security holes that shouldn’t exist, like the one WinRing0 used to gain kernel-level access.

It’s unclear why it took Microsoft so long to address WinRing0. That doesn’t mean that software that uses it is completely useless, though. You can still use it if you want. But you’re likely putting your system at risk by doing so.

Why Windows identifies random apps as threats
Run Windows Defender Scan in Windows Security settings

Unfortunately, there is a workaround, but it’s unlikely to work. According to comments on GitHub, the vulnerability found in WinRing0 has been patched. However, getting it approved and signed by Microsoft is unlikely, as the open source community behind it doesn’t believe they have the resources to get Microsoft to sign the latest version. And without Microsoft’s signature, you won’t be able to install it on your Windows system.

The only other alternative is for each of these application developers to create their own software to access kernel-level permissions. But that is an expensive endeavor that many of them cannot afford. Even if they did, it would likely result in additional costs for users of their software through software purchases.

If you use any of the monitoring software mentioned above, or if you notice Windows Defender warning you about WinRing0 on your system, then there’s probably nothing to worry about at the moment. However, it’s always better to be safe than sorry, especially when it comes to software with kernel-level access like this.

Sign up and earn $1000 a day ⋙

Leave a Comment

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

If you asked five Windows users to explain what Vista's Digital Rights Management (DRM) is, you'd probably get five different answers. But there's one thing that's important.

How to get the newly released Windows 11 24H2 update

How to get the newly released Windows 11 24H2 update

Windows 11 is expected to receive two notable major updates this year.

Word now supports summarizing super long documents

Word now supports summarizing super long documents

Microsoft has officially announced a very useful new feature for Word users, allowing for easier processing of long documents with the help of AI.

How to check computer CPU temperature?

How to check computer CPU temperature?

Let's learn with WebTech360 how to check your computer's CPU temperature in the article below!

Microsoft Edge Game Assist is now available, whats new?

Microsoft Edge Game Assist is now available, whats new?

Back in late November 2024, Microsoft announced Edge Game Assist—a new feature that makes it easier to browse the internet while playing games on your computer.

Instructions for changing computer wallpaper for Windows

Instructions for changing computer wallpaper for Windows

With the default wallpapers on Windows sometimes make us bored. So instead of using those default wallpapers, refresh and change them to bring newness to work and affirm your own personality through the wallpaper of this computer.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft recently raised the price of its Microsoft 365 subscription, justifying the change by adding more AI experiences to the service.

Microsoft is making Windows the ideal operating system for music makers.

Microsoft is making Windows the ideal operating system for music makers.

At the Qualcomm Snapdragon Summit on October 22, Microsoft announced a series of improvements coming to Windows PCs that will improve the overall experience for musicians, music producers, and other audio professionals.

Customize Default User Profile in Windows 7 – Part 1

Customize Default User Profile in Windows 7 – Part 1

In this series of articles we will introduce you to how to customize the default user profile in Windows 7.

New Vulkan SDK Released, Allowing Developers to Build Native Vulkan API Apps for Windows on Arm Platforms

New Vulkan SDK Released, Allowing Developers to Build Native Vulkan API Apps for Windows on Arm Platforms

The launch of the new Copilot+ series of PCs powered by the Snapdragon X Elite processor based on Arm architecture is driving increased interest from developers in building native games and apps specifically for this emerging market segment.

How to run multiple instances of a Windows program

How to run multiple instances of a Windows program

There are a number of ways you can run a different version of the same application. The following guide will explain which method is best for a particular type of program.

Windows Mail is going away, what should I know?

Windows Mail is going away, what should I know?

After a long period of “living on the sidelines,” the Windows Mail, Calendar, and People apps are slowly approaching the end of their lifecycles. Microsoft recently updated its official documentation to clarify that the aforementioned apps will be completely retired on December 31, 2024.

Clipboard History: One of Windows Most Useful and Often Overlooked Features

Clipboard History: One of Windows Most Useful and Often Overlooked Features

Perhaps many of us have used Windows PCs for decades, but are completely unaware of Clipboard and how to take advantage of this useful feature to improve our work performance.

How to block application installation on non-system drives Windows 11

How to block application installation on non-system drives Windows 11

If you want to block application installation on drives other than the system drive, you can disable this feature via Group Policy or Registry Editor.

How to check application version installed on Windows 11

How to check application version installed on Windows 11

Although updates are installed automatically, sometimes you may need to check the version of an application on Windows.

4 ways to quickly open the network connection tool on Windows

4 ways to quickly open the network connection tool on Windows

Whether you're a casual Windows user or a professional technician, knowing how to quickly open Network Connections will help you manage your network more efficiently.

How to Use Clipboard History in Windows 10

How to Use Clipboard History in Windows 10

Windows clipboard history got a major overhaul with the Windows 10 October update.

5 ways to turn off Windows 11 Update, stop updating Win 11

5 ways to turn off Windows 11 Update, stop updating Win 11

In this article, WebTech360 will guide you how to turn off Windows Update on Windows 11 operating system.

How to fix missing Language bar on Windows 10

How to fix missing Language bar on Windows 10

Language bar disappeared on Windows 10? Follow these solutions.

4 Tips to Get the Most Out of the Windows Clipboard

4 Tips to Get the Most Out of the Windows Clipboard

From pinning frequent items to syncing them across multiple devices, here are four great tips that will help you get the most out of the Windows Clipboard.

Microsoft is bringing annoying Windows 11 Start menu ads to Windows 10

Microsoft is bringing annoying Windows 11 Start menu ads to Windows 10

Microsoft continues to announce plans to add new features to Windows 10, despite the fact that the operating system will inevitably die in October 2025.

How to fix Operating system not found error on Windows

How to fix Operating system not found error on Windows

Of all the errors, glitches, and problems you can encounter while using Windows 10, a few messages can leave you feeling truly terrified, such as the Operating system not found screen.

How to Get Rid of Ads on Windows 11 Devices

How to Get Rid of Ads on Windows 11 Devices

Microsoft allows users to disable ads from Windows 11, but the process isn't straightforward. Here are different ways to remove ads from your Windows 11 device.

How to hide phone notification icons in Windows 11 Start menu

How to hide phone notification icons in Windows 11 Start menu

The Phone Link app on Windows lets you link your phone and PC. And you can check your device's battery and connection status,... right from the Start menu.

Invite to download Dynamic wallpaper pack designed for Windows 11 but canceled at the last minute

Invite to download Dynamic wallpaper pack designed for Windows 11 but canceled at the last minute

Besides elements like new interface and features, another aspect, although small, also receives a lot of attention on Windows: wallpaper packs designed and introduced by Microsoft for special occasions.

Microsoft stops supporting Windows Remote Desktop app, moves to new Windows app

Microsoft stops supporting Windows Remote Desktop app, moves to new Windows app

Microsoft has made an important announcement for customers using the Remote Desktop for Windows app from the Microsoft Store. On May 27, 2025, this app will be officially discontinued and removed from the Microsoft Store.

How to Control and Customize Notifications in Windows 11

How to Control and Customize Notifications in Windows 11

With a constant stream of notifications and alerts on your Windows 11 laptop, staying focused becomes a challenge. So take control and customize your notifications to suit your needs.

Windows 12: Expected price, release date, specs, and more rumors

Windows 12: Expected price, release date, specs, and more rumors

Windows 12 is a potential future update to the Windows operating system. It is expected to be released in 2024, although there has been no official confirmation from Microsoft yet.