Why Windows identifies random apps as threats

Some Windows PC owners woke up earlier this week to find their computers suddenly receiving spam messages from Windows Defender warning them about a new “HackTool” called WinRing0. While these warnings are certainly concerning, chances are your computer isn’t actually under attack—at least not yet. But that doesn’t mean you should ignore the warnings.

Why WinRing0 started activating Windows Defender

The problem with random alerts like this is that it's not always clear what the threat is or why Defender considers it a threat. In the case of WinRing0, it's because an exploit in that kernel-level software has previously been linked to dangerous malware (as BleepingComputer reported).

Having kernel-level access essentially means that WinRing0 has access to core components and resources of the operating system. That's a dangerous gamble if the software can be exploited in some way, and it appears that WinRing0 has become the primary driver behind how the SteelFox malware operates and gains access to infected systems.

Even if you've taken the effort to harden your Windows PC's security with Defender, malware like SteelFox can still use the vulnerability found in WinRing0 to bypass your protections.

Another big problem with software like WinRing0 is that it tends to find its way into a lot of different software. That’s the case with this latest Windows Defender warning, which The Verge reports is part of a number of widely used PC fan control apps, including Fan Control, which was mentioned a few years ago.

Windows Defender also seems to trigger the warning if you have other third-party monitoring software installed, including Libre Hardware Monitor, MSI Afterburner , SteelSeries Engine, Razer Synapse, OmenMon, etc.

This is not surprising.

The overall impact of this on monitoring software like Afterburner and Fan Control is clear. Unless Microsoft provides some way for these apps to access these low-level permissions in the future, you’re taking a huge security risk by installing and using any of them.

The move isn’t entirely unexpected, however. Last year’s massive CrowdStrike breach had dire consequences for many companies, including some in the healthcare industry. Since then, Microsoft has been under a lot of pressure to close security holes that shouldn’t exist, like the one WinRing0 used to gain kernel-level access.

It’s unclear why it took Microsoft so long to address WinRing0. That doesn’t mean that software that uses it is completely useless, though. You can still use it if you want. But you’re likely putting your system at risk by doing so.

Why Windows identifies random apps as threats
Run Windows Defender Scan in Windows Security settings

Unfortunately, there is a workaround, but it’s unlikely to work. According to comments on GitHub, the vulnerability found in WinRing0 has been patched. However, getting it approved and signed by Microsoft is unlikely, as the open source community behind it doesn’t believe they have the resources to get Microsoft to sign the latest version. And without Microsoft’s signature, you won’t be able to install it on your Windows system.

The only other alternative is for each of these application developers to create their own software to access kernel-level permissions. But that is an expensive endeavor that many of them cannot afford. Even if they did, it would likely result in additional costs for users of their software through software purchases.

If you use any of the monitoring software mentioned above, or if you notice Windows Defender warning you about WinRing0 on your system, then there’s probably nothing to worry about at the moment. However, it’s always better to be safe than sorry, especially when it comes to software with kernel-level access like this.

Sign up and earn $1000 a day ⋙

Leave a Comment

Microsoft Launches New Sticky Notes App for Windows 11

Microsoft Launches New Sticky Notes App for Windows 11

After keeping things the same for years, the Sticky Note update in mid-2024 changed the game.

6 Ways to Copy File and Folder Paths in Windows 11

6 Ways to Copy File and Folder Paths in Windows 11

Paths are the locations of files or folders in Windows 11. All paths include the folders you need to open to get to a specific location.

Learning from Apple, Microsoft is also about to have Windows Intelligence

Learning from Apple, Microsoft is also about to have Windows Intelligence

Recently, clues that Microsoft will likely "follow the path" of Apple in the field of artificial intelligence have gradually been revealed.

How to Set Windows Photo Viewer as Default Photo Viewer on Windows 11

How to Set Windows Photo Viewer as Default Photo Viewer on Windows 11

Windows Photo Viewer was first released alongside Windows XP and has quickly become one of the most frequently used tools on Windows.

Restore hidden folders in Windows when infected with virus

Restore hidden folders in Windows when infected with virus

In many cases, it is usually due to virus attacks that the hidden folders of the system cannot be displayed even after activating the “Show hidden files and folders” option in Folder Options. Some of the following methods will help to handle this problem.

ExpressVPN Now Supports Windows ARM PCs

ExpressVPN Now Supports Windows ARM PCs

One of the world's most popular VPN services - ExpressVPN - has officially launched an app version for Windows PCs running on ARM-based processors.

Download beautiful wallpapers to celebrate Microsofts 50th birthday

Download beautiful wallpapers to celebrate Microsofts 50th birthday

Did you know Microsoft is celebrating its 50th birthday this week?

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection, download now!

Microsoft releases new Fluid Textures desktop wallpaper collection

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

Microsoft Discontinues Support for Legacy DRM on Windows Media Player, Windows 7/8, Silverlight

If you asked five Windows users to explain what Vista's Digital Rights Management (DRM) is, you'd probably get five different answers. But there's one thing that's important.

How to get the newly released Windows 11 24H2 update

How to get the newly released Windows 11 24H2 update

Windows 11 is expected to receive two notable major updates this year.

Word now supports summarizing super long documents

Word now supports summarizing super long documents

Microsoft has officially announced a very useful new feature for Word users, allowing for easier processing of long documents with the help of AI.

How to check computer CPU temperature?

How to check computer CPU temperature?

Let's learn with WebTech360 how to check your computer's CPU temperature in the article below!

Microsoft Edge Game Assist is now available, whats new?

Microsoft Edge Game Assist is now available, whats new?

Back in late November 2024, Microsoft announced Edge Game Assist—a new feature that makes it easier to browse the internet while playing games on your computer.

Instructions for changing computer wallpaper for Windows

Instructions for changing computer wallpaper for Windows

With the default wallpapers on Windows sometimes make us bored. So instead of using those default wallpapers, refresh and change them to bring newness to work and affirm your own personality through the wallpaper of this computer.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft allows users to use Office applications on Windows for free, but with some limitations.

Microsoft recently raised the price of its Microsoft 365 subscription, justifying the change by adding more AI experiences to the service.

Fix Windows Error Code 0xc0000098: Backup ACPI.sys to Prevent Boot Failure

Fix Windows Error Code 0xc0000098: Backup ACPI.sys to Prevent Boot Failure

Error code 0xc0000098 in Windows causes a blue screen error on startup. The ACPI.sys driver is often to blame, especially on unsupported versions of Windows 11 like 23H2 or 22H2 or Windows 10.

Quickly fix Windows 10/8/7 computer error that freezes and cannot exit Safe Mode

Quickly fix Windows 10/8/7 computer error that freezes and cannot exit Safe Mode

In some cases, sometimes you start your computer in Safe Mode and the computer freezes. So how to fix the error in this case, please refer to the article below of WebTech360.

How to fix Snipping Tool keeps showing error

How to fix Snipping Tool keeps showing error

Snipping Tool is a powerful photo and video capture tool on Windows. However, this tool sometimes has some errors, such as constantly displaying on the screen.

How to get the fastest internet connection from your router

How to get the fastest internet connection from your router

Every network has a router to access the Internet, but not everyone knows how to make the router work better. In this article, we will introduce some router tips to help speed up the wireless connection in the network.

Common Mistakes When Performing Internet Speed ​​Tests

Common Mistakes When Performing Internet Speed ​​Tests

If the results seem slower than expected, don't be too quick to blame your ISP - mistakes when performing the test can skew your numbers.

What is QoS? How to use QoS for faster Internet speeds when you need it most

What is QoS? How to use QoS for faster Internet speeds when you need it most

In the article below, we will introduce and guide you to learn about the concept of QoS - Quality of Service on router devices.

Why cant this built-in Credential Manager feature in Windows replace a password manager?

Why cant this built-in Credential Manager feature in Windows replace a password manager?

Windows has a built-in Credential Manager, but it's not what you think it is—and certainly not a replacement for a password manager.

How to install free HEVC codecs on Windows 10 (for H.265 video)

How to install free HEVC codecs on Windows 10 (for H.265 video)

Microsoft charges for its official codecs and doesn't include them in Windows 10. However, you can get them for free without pulling out your credit card and spending $0.99.

Instructions to fix Access Denied error when accessing files or folders on Windows

Instructions to fix Access Denied error when accessing files or folders on Windows

While having trouble accessing files and folders can be frustrating, don't panic—with a few simple tweaks, you can regain access to your system.

How to check if USB Boot has been created successfully?

How to check if USB Boot has been created successfully?

After creating a USB boot to install Windows, users should check the USB boot's performance to see if it was created successfully or not.

4 Types of Windows Data That Are Growing in Size: How to Control Them?

4 Types of Windows Data That Are Growing in Size: How to Control Them?

Although Windows Storage Sense efficiently deletes temporary files, some types of data are permanent and continue to accumulate.

How to turn off background apps in Windows 11, reduce RAM consumption on Win 11

How to turn off background apps in Windows 11, reduce RAM consumption on Win 11

You can turn off Windows 11 background apps to optimize performance, save battery and reduce RAM consumption.

Instructions to fix the error “Network path was not found” in Windows

Instructions to fix the error “Network path was not found” in Windows

When a computer, mobile device, or printer tries to connect to a Microsoft Windows computer over a network, for example, the error message network path was not found — Error 0x80070035 may appear.

How to block Internet connection of Windows 10 software and applications

How to block Internet connection of Windows 10 software and applications

We can block Internet access for any application or software on the computer, while other programs can still access the network. The following article will guide readers on how to disable Internet access for software and applications on Windows.

How to Stay Safe on Windows 10 Until 2030

How to Stay Safe on Windows 10 Until 2030

Instead of paying $30 for a year of security updates, keep Windows 10 safe until 2030 with this simple solution.