• 10.09.2025, 08:59
  • Register
  • Login
  • You are not logged in.

 

Dear visitor, welcome to Aqua Computer Forum. If this is your first visit here, please read the Help. It explains how this page works. You must be registered before you can use all the page's features. Please use the registration form, to register here or read more information about the registration process. If you are already registered, please login here.

Shoggy

Sven - Admin

Information about Windows Defender warning "HackTool:Win32/Winring0" (AquaComputerService.sys)

Wednesday, March 12th 2025, 11:47am

Windows Defender and other antivirus software (repeatedly) detect the AquaComputerService.sys file as a threat or virus.



This is not a virus!

This file is a driver that aquasuite has been using for many years for hardware monitoring (e.g. CPU temperature). The exact same driver is also used by numerous other, far more popular programs and companies.

A security vulnerability (CVE-2020-14979) has been known to exist in this driver for some time. The problem is that the driver lacks a security descriptor and can be accessed with user rights. Since the driver has deep access to the system, it is possible to execute malicious code.

Regardless of the version, aquasuite applies a security descriptor when installing the driver, which restricts access to system and admin rights. Based on current knowledge and our own tests, the attack scenario is no longer feasible.

Please note: If any other application installs the driver before aquasuite without a corresponding security descriptor, the driver is vulnerable. In this case, this is a failure on the part of the corresponding application.

We are already working on a solution by creating our own customized version of the driver and having it certified by Microsoft. However, this is a complex process and will therefore take some time.

If you do not see any problems with using the driver, you can define it as an exception. Alternatively, you can deactivate all hardware monitor modules in aquasuite via the aquasuite -> Service tab. This will prevent aquasuite from loading the corresponding driver. System data can still be transferred to aquasuite via HWiNFO or AIDA64 if required.