• Hacktool:Win32/Winring0

    • This topic has 13 replies, 4 voices, and was last updated 2 months ago.
    Author
    Topic
    #2755199

    Hello !

    Yesterday I got a message from Microsfot Defenders about Hacktool:Win32/Winring0 in WinRing0x64.

    I’m not the only one as you can see here: https://www.reddit.com/r/techsupport/comments/1j8jrs8/hack_tool_win32winring0/

    For now I clicked on ignore but I’m afraid to restart my PC, could you tell me what to do plz ?

     

    Viewing 10 reply threads
    Author
    Replies
    • #2755260

      C:\Windows\system32\Drivers\WinRing0x64.sys has been flagged up occasionally after utility driver updates for over a decade, maybe two.

      I’d put it in quarantine for a while in case of some wag trying a double-bluff.

      Virustotal (mentioned in the reddit thread) gives it the okay from almost all the major (read trusted) AV companies, but something (an update, new software using it?) has changed.

      If you know which utility software it belongs to (there are many using it) then you can allow deletion of the driver and look for a replacement or updated software in a week or so.

      1 user thanked author for this post.
    • #2755264

      Thanks for your answer Satrow.

      Defenders seems to have put it in quarantine, I’ll let it for now but I hope I’ll not have problems when I’ll restart my PC like some people on Reddit : S

      I have no idea which utility software it belongs to, is there a way to discover it ?

    • #2755288

      Not so easy – you’ll need to look for stuff like fan controllers, software that shows/measures temps/voltages/speeds etc. Many hardware/utility companies utilise it.

      Probably best for you to list what you have in that range, if it’s only a few, which one runs automatically (Autoruns/TaskMan’s Startup apps tab… )?

      1 user thanked author for this post.
    • #2755294

      Ah it must be Gigabyte Control Center then.

    • #2755296

      My Anti-virus (AVG) sometimes does the same thing for part of one or more of the utility programs I use and it almost always winds up being a false positive.

      Heck, I’ve even had my AVG block updates for a few of my utilities (7+ Taskbar Tweaker, Balaboka text 2 speech, Open-Shell, etc.) because it quarantined part of the actual installation program. And it does so even though it accepts the actual programs themselves as being virus/malware free!

      The problem is, some utility programs, like what @satrow mentioned, use modules that can “appear” to be malware because of how they access the OS/system to do what they do.

      3 users thanked author for this post.
    • #2755309

      Gigabyte Control Center

      Yup, that’ll be the most likely – and it could have bitten me too but I’d uninstalled it after not using it for a couple of months.

      1 user thanked author for this post.
    • #2755325

      Thanks again for your answer, I’ll let you know how the restart went.

    • #2755460

      I don’t see any change so it’s all good !!

       

      1 user thanked author for this post.
    • #2755660

      https://github.com/Rem0o/FanControl.Releases/releases/tag/V217

      Many of you reported that Defender started to flag the LibreHardwareMonitorLib driver (WinRing0x64.sys), you do not need to report it furthermore, I\u0027m aware of it. This kernel driver always had a known vulnerability that could be theoretically be exploited on an infected machine. The driver or the program itself are not malicious and are not more or less secure than before it got flagged. It is good practice to review the risk before any action is taken with Defender

      * May not be false positive :

      https://nvd.nist.gov/vuln/detail/cve-2020-14979

      The WinRing0.sys and WinRing0x64.sys drivers 1.2.0 in EVGA Precision X1 through 1.0.6 allow local users, including low integrity processes, to read and write to arbitrary memory locations. This allows any user to gain NT AUTHORITY\SYSTEM privileges by mapping \Device\PhysicalMemory into the calling process.

      1 user thanked author for this post.
    • #2755673

      I’ll follow the advice of Satrow and update the software, I don’t really know what else to do.

      1 user thanked author for this post.
    • #2755677

      allow local users

      Yes, we should all worry about people with access to our machines tweaking them to run cooler and quieter….

      Better allow them to open the windows and wear ear defenders, so sneak thieves can relocate them somewhere safe?

      Ring0 is the Windows kernel, some software must have access to portions of that to measure/control base hardware and settings.

      Update if the software you use is actually required for your needs. Lock the door when you leave.

      1 user thanked author for this post.
      • #2755744

        https://insider.razer.com/general-discussion-6/hack-tool-win32-winring0-razer-synapse-74634?postid=249278#post249278

        “Windows virus and threat protection has flagged โ€œHacktool:Win32/Winring0โ€ as an active high threat. This is my first encounter with a piece of malware. affected razor synapse everyone else?”

        “Synapse 3 rolled out a security patch on February 20, 2025, to move away from these drivers.

        Synapse 4 did not use these drivers.

        We encourage anyone facing this issue to check that they are using the latest version of Synapse 3, or upgrade to Synapse 4 for the most advanced protection and features.

        This is in line with whatโ€™s being handled throughout the industry. We went ahead and made sure everything is secure ahead of time, but itโ€™s very important that users are up to date with their Windows security patches and any others where required.”

        https://www.razer.com/synapse-3

    Viewing 10 reply threads
    Reply To: Reply #2755294 in Hacktool:Win32/Winring0

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




    Cancel