Why Windows identifies random apps as threats

Some Windows PC owners woke up earlier this week to find their computers suddenly receiving spam messages from Windows Defender warning them about a new “HackTool” called WinRing0. While these warnings are certainly concerning, chances are your computer isn’t actually under attack—at least not yet. But that doesn’t mean you should ignore the warnings.

Why WinRing0 started activating Windows Defender

The problem with random alerts like this is that it's not always clear what the threat is or why Defender considers it a threat. In the case of WinRing0, it's because an exploit in that kernel-level software has previously been linked to dangerous malware (as BleepingComputer reported).

Having kernel-level access essentially means that WinRing0 has access to core components and resources of the operating system. That's a dangerous gamble if the software can be exploited in some way, and it appears that WinRing0 has become the primary driver behind how the SteelFox malware operates and gains access to infected systems.

Even if you've taken the effort to harden your Windows PC's security with Defender, malware like SteelFox can still use the vulnerability found in WinRing0 to bypass your protections.

Another big problem with software like WinRing0 is that it tends to find its way into a lot of different software. That’s the case with this latest Windows Defender warning, which The Verge reports is part of a number of widely used PC fan control apps, including Fan Control, which was mentioned a few years ago.

Windows Defender also seems to trigger the warning if you have other third-party monitoring software installed, including Libre Hardware Monitor, MSI Afterburner , SteelSeries Engine, Razer Synapse, OmenMon, etc.

This is not surprising.

The overall impact of this on monitoring software like Afterburner and Fan Control is clear. Unless Microsoft provides some way for these apps to access these low-level permissions in the future, you’re taking a huge security risk by installing and using any of them.

The move isn’t entirely unexpected, however. Last year’s massive CrowdStrike breach had dire consequences for many companies, including some in the healthcare industry. Since then, Microsoft has been under a lot of pressure to close security holes that shouldn’t exist, like the one WinRing0 used to gain kernel-level access.

It’s unclear why it took Microsoft so long to address WinRing0. That doesn’t mean that software that uses it is completely useless, though. You can still use it if you want. But you’re likely putting your system at risk by doing so.

Why Windows identifies random apps as threats
Run Windows Defender Scan in Windows Security settings

Unfortunately, there is a workaround, but it’s unlikely to work. According to comments on GitHub, the vulnerability found in WinRing0 has been patched. However, getting it approved and signed by Microsoft is unlikely, as the open source community behind it doesn’t believe they have the resources to get Microsoft to sign the latest version. And without Microsoft’s signature, you won’t be able to install it on your Windows system.

The only other alternative is for each of these application developers to create their own software to access kernel-level permissions. But that is an expensive endeavor that many of them cannot afford. Even if they did, it would likely result in additional costs for users of their software through software purchases.

If you use any of the monitoring software mentioned above, or if you notice Windows Defender warning you about WinRing0 on your system, then there’s probably nothing to worry about at the moment. However, it’s always better to be safe than sorry, especially when it comes to software with kernel-level access like this.

Sign up and earn $1000 a day ⋙

Leave a Comment

Microsoft Launches New Sticky Notes App for Windows 11

Microsoft Launches New Sticky Notes App for Windows 11

After keeping things the same for years, the Sticky Note update in mid-2024 changed the game.

6 Ways to Copy File and Folder Paths in Windows 11

6 Ways to Copy File and Folder Paths in Windows 11

Paths are the locations of files or folders in Windows 11. All paths include the folders you need to open to get to a specific location.

Learning from Apple, Microsoft is also about to have Windows Intelligence

Learning from Apple, Microsoft is also about to have Windows Intelligence

Recently, clues that Microsoft will likely "follow the path" of Apple in the field of artificial intelligence have gradually been revealed.

How to Set Windows Photo Viewer as Default Photo Viewer on Windows 11

How to Set Windows Photo Viewer as Default Photo Viewer on Windows 11

Windows Photo Viewer was first released alongside Windows XP and has quickly become one of the most frequently used tools on Windows.

Restore hidden folders in Windows when infected with virus

Restore hidden folders in Windows when infected with virus

In many cases, it is usually due to virus attacks that the hidden folders of the system cannot be displayed even after activating the “Show hidden files and folders” option in Folder Options. Some of the following methods will help to handle this problem.

ExpressVPN Now Supports Windows ARM PCs

ExpressVPN Now Supports Windows ARM PCs

One of the world's most popular VPN services - ExpressVPN - has officially launched an app version for Windows PCs running on ARM-based processors.

Download beautiful wallpapers to celebrate Microsofts 50th birthday

Download beautiful wallpapers to celebrate Microsofts 50th birthday

Did you know Microsoft is celebrating its 50th birthday this week?

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

If you asked five Windows users to explain what Vista's Digital Rights Management (DRM) is, you'd probably get five different answers. But there's one thing that's important.

How to get the newly released Windows 11 24H2 update

How to get the newly released Windows 11 24H2 update

Windows 11 is expected to receive two notable major updates this year.

Word now supports summarizing super long documents

Word now supports summarizing super long documents

Microsoft has officially announced a very useful new feature for Word users, allowing for easier processing of long documents with the help of AI.

How to check computer CPU temperature?

How to check computer CPU temperature?

Let's learn with WebTech360 how to check your computer's CPU temperature in the article below!

Microsoft Edge Game Assist is now available, whats new?

Microsoft Edge Game Assist is now available, whats new?

Back in late November 2024, Microsoft announced Edge Game Assist—a new feature that makes it easier to browse the internet while playing games on your computer.

Instructions for changing computer wallpaper for Windows

Instructions for changing computer wallpaper for Windows

With the default wallpapers on Windows sometimes make us bored. So instead of using those default wallpapers, refresh and change them to bring newness to work and affirm your own personality through the wallpaper of this computer.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft recently raised the price of its Microsoft 365 subscription, justifying the change by adding more AI experiences to the service.

How to Open and Use MSConfig on Windows 10

How to Open and Use MSConfig on Windows 10

MSConfig is a versatile tool that is great for managing the startup process on your computer. It can also be used for more than just troubleshooting performance and stability issues.

6 Ways to Run Software with Administrator Rights in Windows

6 Ways to Run Software with Administrator Rights in Windows

Running some programs with administrator rights is often necessary for full functionality, especially for system tools or file editing and settings software.

How to fix BSOD Memory Management error

How to fix BSOD Memory Management error

Have you ever encountered the Windows Memory Management blue screen of death error? This common Windows Stop Code is annoying, but there are some simple fixes for Windows Memory Management errors.

Most people dont use these hidden features in Windows Security.

Most people dont use these hidden features in Windows Security.

Windows Security does more than just protect against basic viruses. It protects against phishing, blocks ransomware, and prevents malicious apps from running. However, these features aren't easy to spot—they're hidden behind layers of menus.

Follow these 7 steps to keep Windows 11 from slowing down again!

Follow these 7 steps to keep Windows 11 from slowing down again!

From deleting temporary files to updating software, there are many simple and effective ways to keep your computer running smoothly like new.

Heres how to create a virtual hard drive (Virtual Hard Disk) on Windows 10

Heres how to create a virtual hard drive (Virtual Hard Disk) on Windows 10

Basically, a Virtual Hard Disk (VHD) is a file format that contains structures that are “exactly” identical to the structure of a hard drive.

Why is there a lock icon on the drive and how to remove it?

Why is there a lock icon on the drive and how to remove it?

Wondering why there is a lock icon on a drive in File Explorer? This article explains what it is and how to remove the lock icon from a drive in Windows 10.

How to use SpeedFan to check CPU temperature and computer fan speed

How to use SpeedFan to check CPU temperature and computer fan speed

SpeedFan tool checks your computer's temperature, CPU usage, and fan speed so you can cool it down.

10 Great Windows Features That Many People Dont Use

10 Great Windows Features That Many People Dont Use

From killing frozen apps right on the taskbar to automatically locking your computer when you walk away, there are plenty of tools you'll wish you'd discovered sooner.

3 Tools You Need to Remove Windows 11 Tracking

3 Tools You Need to Remove Windows 11 Tracking

Don't completely trust the default settings when it comes to privacy. Windows 11 is no exception, as it often oversteps its bounds when it comes to data collection.

How to download Windows 10, download Windows 10 ISO file from Microsoft

How to download Windows 10, download Windows 10 ISO file from Microsoft

When downloading Windows 10 from Microsoft, you will download Windows 10 as an ISO file. From this Windows 10 ISO file, you can use it to create a bootable USB, a Windows installation USB, or a computer ghost. Let's see how to download Windows 10!

Windows 11 is about to let you transfer data from your old PC during setup — heres how

Windows 11 is about to let you transfer data from your old PC during setup — heres how

Microsoft will officially stop supporting Windows 10 in less than three months, which means millions of users will have to upgrade to new hardware to run Windows 11.

How to send password protected files without buying software

How to send password protected files without buying software

You don't need to spend a dime to secure your documents and other important data. Use trusted free apps to lock everything down and send it securely to anyone.

6 Free Tools That Tell You Your Hard Drive Is About to Fail

6 Free Tools That Tell You Your Hard Drive Is About to Fail

Several free tools can predict drive failures before they happen, giving you time to back up your data and replace the drive in time.

How to fix WHEA Uncorrectable Error on Windows 10/11

How to fix WHEA Uncorrectable Error on Windows 10/11

Blue screen errors, also known as blue screen of death, have been around for a long time on Windows. These errors contain important information related to the sudden crash of the system.