TrafficMonitor icon indicating copy to clipboard operation
TrafficMonitor copied to clipboard

TrafficMonitor.sys - VulnerableDriver:WinNT/Wnring0.G

Open Shionsan opened this issue 3 months ago • 6 comments

Prerequisites

  • [x] I have searched for related issues in the issues list.
  • [x] I have read the FAQ in detail and searched for related issues in FAQ list.

Current TrafficMonitor Version

1.85.1

Current Operating System Version

Windows 10 (10.0.19045)

What happened?

Windows Defender recognizes your driver as vulnerable and wants to remove it!

TrafficMonitor.sys - VulnerableDriver:WinNT/Wnring0.G.

Details: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=VulnerableDriver%3AWinNT%2FWinring0.G&threatid=2147947097

Log Output


Additional Information

No response

Shionsan avatar Sep 03 '25 21:09 Shionsan

I also encountered the same problem

deepsea52418 avatar Sep 04 '25 15:09 deepsea52418

i got same problem. i delete it.

leenom avatar Sep 04 '25 17:09 leenom

Same happening here. From Virustotal (https://www.virustotal.com/gui/file/11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5/community), here are some comments:

"File is flagged because it is the WinRing0x64.sys driver, used by many software suites for accessing hardware at Ring 0. Primarily for RGB and Fan Control on PCs. Driver itself is considered vulnerable by many if malicious programs hook into it, but the file/driver itself is not malicious.

Use with caution."

"This is a "vulnerable driver" from the byovd list. The file itself is not malicious, but it's a signed driver that when installed, allows unlimited system access. Probably not what you want. Therefore this file is also included in various malware code. Google for "byovd" to find out more."

RunyangWang avatar Sep 04 '25 22:09 RunyangWang

same here.

songlake avatar Sep 06 '25 02:09 songlake

Maybe the program can switch to using this when it's released? It's closed source though. I'm going to use only TrafficMonitor lite until this is fixed.

thename2468 avatar Sep 14 '25 22:09 thename2468

Same here. Too many security threats!

Image

KertLynx avatar Sep 19 '25 03:09 KertLynx