Why Windows identifies random apps as threats

Some Windows PC owners woke up earlier this week to find their computers suddenly receiving spam messages from Windows Defender warning them about a new “HackTool” called WinRing0. While these warnings are certainly concerning, chances are your computer isn’t actually under attack—at least not yet. But that doesn’t mean you should ignore the warnings.

Why WinRing0 started activating Windows Defender

The problem with random alerts like this is that it's not always clear what the threat is or why Defender considers it a threat. In the case of WinRing0, it's because an exploit in that kernel-level software has previously been linked to dangerous malware (as BleepingComputer reported).

Having kernel-level access essentially means that WinRing0 has access to core components and resources of the operating system. That's a dangerous gamble if the software can be exploited in some way, and it appears that WinRing0 has become the primary driver behind how the SteelFox malware operates and gains access to infected systems.

Even if you've taken the effort to harden your Windows PC's security with Defender, malware like SteelFox can still use the vulnerability found in WinRing0 to bypass your protections.

Another big problem with software like WinRing0 is that it tends to find its way into a lot of different software. That’s the case with this latest Windows Defender warning, which The Verge reports is part of a number of widely used PC fan control apps, including Fan Control, which was mentioned a few years ago.

Windows Defender also seems to trigger the warning if you have other third-party monitoring software installed, including Libre Hardware Monitor, MSI Afterburner , SteelSeries Engine, Razer Synapse, OmenMon, etc.

This is not surprising.

The overall impact of this on monitoring software like Afterburner and Fan Control is clear. Unless Microsoft provides some way for these apps to access these low-level permissions in the future, you’re taking a huge security risk by installing and using any of them.

The move isn’t entirely unexpected, however. Last year’s massive CrowdStrike breach had dire consequences for many companies, including some in the healthcare industry. Since then, Microsoft has been under a lot of pressure to close security holes that shouldn’t exist, like the one WinRing0 used to gain kernel-level access.

It’s unclear why it took Microsoft so long to address WinRing0. That doesn’t mean that software that uses it is completely useless, though. You can still use it if you want. But you’re likely putting your system at risk by doing so.

Why Windows identifies random apps as threats
Run Windows Defender Scan in Windows Security settings

Unfortunately, there is a workaround, but it’s unlikely to work. According to comments on GitHub, the vulnerability found in WinRing0 has been patched. However, getting it approved and signed by Microsoft is unlikely, as the open source community behind it doesn’t believe they have the resources to get Microsoft to sign the latest version. And without Microsoft’s signature, you won’t be able to install it on your Windows system.

The only other alternative is for each of these application developers to create their own software to access kernel-level permissions. But that is an expensive endeavor that many of them cannot afford. Even if they did, it would likely result in additional costs for users of their software through software purchases.

If you use any of the monitoring software mentioned above, or if you notice Windows Defender warning you about WinRing0 on your system, then there’s probably nothing to worry about at the moment. However, it’s always better to be safe than sorry, especially when it comes to software with kernel-level access like this.

Sign up and earn $1000 a day ⋙

Leave a Comment

Microsoft Launches New Sticky Notes App for Windows 11

Microsoft Launches New Sticky Notes App for Windows 11

After keeping things the same for years, the Sticky Note update in mid-2024 changed the game.

6 Ways to Copy File and Folder Paths in Windows 11

6 Ways to Copy File and Folder Paths in Windows 11

Paths are the locations of files or folders in Windows 11. All paths include the folders you need to open to get to a specific location.

Learning from Apple, Microsoft is also about to have Windows Intelligence

Learning from Apple, Microsoft is also about to have Windows Intelligence

Recently, clues that Microsoft will likely "follow the path" of Apple in the field of artificial intelligence have gradually been revealed.

How to Set Windows Photo Viewer as Default Photo Viewer on Windows 11

How to Set Windows Photo Viewer as Default Photo Viewer on Windows 11

Windows Photo Viewer was first released alongside Windows XP and has quickly become one of the most frequently used tools on Windows.

Restore hidden folders in Windows when infected with virus

Restore hidden folders in Windows when infected with virus

In many cases, it is usually due to virus attacks that the hidden folders of the system cannot be displayed even after activating the “Show hidden files and folders” option in Folder Options. Some of the following methods will help to handle this problem.

ExpressVPN Now Supports Windows ARM PCs

ExpressVPN Now Supports Windows ARM PCs

One of the world's most popular VPN services - ExpressVPN - has officially launched an app version for Windows PCs running on ARM-based processors.

Download beautiful wallpapers to celebrate Microsofts 50th birthday

Download beautiful wallpapers to celebrate Microsofts 50th birthday

Did you know Microsoft is celebrating its 50th birthday this week?

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

If you asked five Windows users to explain what Vista's Digital Rights Management (DRM) is, you'd probably get five different answers. But there's one thing that's important.

How to get the newly released Windows 11 24H2 update

How to get the newly released Windows 11 24H2 update

Windows 11 is expected to receive two notable major updates this year.

Word now supports summarizing super long documents

Word now supports summarizing super long documents

Microsoft has officially announced a very useful new feature for Word users, allowing for easier processing of long documents with the help of AI.

How to check computer CPU temperature?

How to check computer CPU temperature?

Let's learn with WebTech360 how to check your computer's CPU temperature in the article below!

Microsoft Edge Game Assist is now available, whats new?

Microsoft Edge Game Assist is now available, whats new?

Back in late November 2024, Microsoft announced Edge Game Assist—a new feature that makes it easier to browse the internet while playing games on your computer.

Instructions for changing computer wallpaper for Windows

Instructions for changing computer wallpaper for Windows

With the default wallpapers on Windows sometimes make us bored. So instead of using those default wallpapers, refresh and change them to bring newness to work and affirm your own personality through the wallpaper of this computer.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft recently raised the price of its Microsoft 365 subscription, justifying the change by adding more AI experiences to the service.

How to fix “Well Need Your Current Windows Password” error on Windows 10/11

How to fix “Well Need Your Current Windows Password” error on Windows 10/11

Are you getting the “We'll need your current Windows password one last time” error? This annoying pop-up can prevent you from getting things done.

Quickly fix Unmountable Boot Volume error on Windows 10/11

Quickly fix Unmountable Boot Volume error on Windows 10/11

The Unmountable Boot Volume error occurs due to some installed software conflicting with the operating system or due to the computer suddenly shutting down,... In the article below, WebTech360 will guide you through some ways to fix this error.

How to Fix Clipboard History Error in Windows 11 Latest Update

How to Fix Clipboard History Error in Windows 11 Latest Update

If you use Clipboard History to store data for later use, there is a small chance that the data will remain empty no matter what you try.

How to remove Copilot and other AI features in Windows

How to remove Copilot and other AI features in Windows

If you don't care about having extra bloatware on your system, there are ways to remove or disable Windows Copilot on Windows 11.

Why is the laptop battery percentage estimate never accurate?

Why is the laptop battery percentage estimate never accurate?

Most laptop users have encountered a situation where Windows shows 2 hours of battery life left, then five minutes later it jumps to 5 hours or even 1 hour. Why does this time jump around like that?

10 Windows 11 settings to maximize laptop battery life

10 Windows 11 settings to maximize laptop battery life

Laptop batteries degrade over time and lose capacity, resulting in less battery life. But after tweaking some deeper Windows 11 settings, you should see a significant improvement in battery life.

Microsoft: PCs running Windows 11 21H2/22H2 will be forced to update to 23H2 next month

Microsoft: PCs running Windows 11 21H2/22H2 will be forced to update to 23H2 next month

Windows 11 version 21H2 is one of the major original releases of Windows 11 that began rolling out globally on October 4, 2021.

Microsoft spams Copilot QR codes on Windows 11 lock screen to lure users

Microsoft spams Copilot QR codes on Windows 11 lock screen to lure users

The year 2023 saw Microsoft betting heavily on artificial intelligence and its partnership with OpenAI to make Copilot a reality.

How to Disable User Accounts on Windows 11

How to Disable User Accounts on Windows 11

You can disable User Accounts so that others can no longer access your computer.

Buying a Windows laptop is harder than ever

Buying a Windows laptop is harder than ever

Is the NPU different enough to delay purchase and wait for the PC Copilot+ to become mainstream?

How to turn on and off battery saving mode on Windows 11 laptop

How to turn on and off battery saving mode on Windows 11 laptop

Windows 11's Battery saver mode is a feature designed to extend laptop battery life.

Microsoft Launches New Sticky Notes App for Windows 11

Microsoft Launches New Sticky Notes App for Windows 11

After keeping things the same for years, the Sticky Note update in mid-2024 changed the game.

How to fix IRQL NOT LESS OR EQUAL error on Windows

How to fix IRQL NOT LESS OR EQUAL error on Windows

The IRQL NOT LESS OR EQUAL error is a memory-related error that typically occurs when a system process or driver attempts to access a memory address without proper access permissions.

6 Ways to Copy File and Folder Paths in Windows 11

6 Ways to Copy File and Folder Paths in Windows 11

Paths are the locations of files or folders in Windows 11. All paths include the folders you need to open to get to a specific location.

Compare Windows 10 and Windows 11

Compare Windows 10 and Windows 11

Windows 11 has officially launched, compared to Windows 10 Windows 11 also has many changes, from the interface to new features. Please follow the details in the article below.