That CVE talks about the WinRing0 driver. ThrottleStop has not used the WinRing0 driver for years.CVE-2020–14979
No one has ever contacted me about any malware that is actively exploiting the ThrottleStop.sys driver.being actively exploited by malware
I agree. It could be lights out for ThrottleStop. It was fun while it lasted.Looks this might become wider issue when definitions are spread.
ThrottleStop.exe uses the ThrottleStop.sys driver. This is not the same as the RwDrv.sys driver that RWEverything uses.RwDrv.sys
It is interesting that I am still able to run ThrottleStop while using the newer 1.421.843.0 Windows Defender definitions without any problems. Do you have full Administrator privileges for your account?Currently I'm on 1.421.837.0 definitions (WIN10)
Processor | Ryzen 7 5700X |
---|---|
Memory | 48 GB |
Video Card(s) | RTX 4080 |
Storage | 2x HDD RAID 1, 3x M.2 NVMe |
Display(s) | 30" 2560x1600 + 19" 1280x1024 |
Software | Windows 10 64-bit |
I think an older version of TS used that driver? Maybe MS just blocked TS and assumed all builds use the same driver?ThrottleStop.exe uses the ThrottleStop.sys driver. This is not the same as the RwDrv.sys driver that RWEverything uses.
System Name | "Icy Resurrection" |
---|---|
Processor | 13th Gen Intel Core i9-13900KS Special Edition |
Motherboard | ASUS ROG Maximus Z790 Apex Encore |
Cooling | Noctua NH-D15S upgraded with 2x NF-F12 iPPC-3000 fans and Honeywell PTM7950 TIM |
Memory | 32 GB G.SKILL Trident Z5 RGB F5-6800J3445G16GX2-TZ5RK @ 7600 MT/s 36-44-44-52-96 1.4V |
Video Card(s) | ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition |
Storage | 500 GB WD Black SN750 SE NVMe SSD + 4 TB WD Red Plus WD40EFPX HDD |
Display(s) | 55-inch LG G3 OLED |
Case | Pichau Mancer CV500 White Edition |
Audio Device(s) | Apple USB-C + Sony MDR-V7 headphones |
Power Supply | EVGA 1300 G2 1.3kW 80+ Gold |
Mouse | Microsoft Classic Intellimouse |
Keyboard | IBM Model M type 1391405 (distribución española) |
Software | Windows 11 IoT Enterprise LTSC 24H2 |
Benchmark Scores | I pulled a Qiqi~ |
Sounds like a custom defender rule added by the OP's Company rather than MS?
Maybe. It is all a blur now. That was 15 years ago!I think an older version of TS used that driver?
System Name | Obliterator |
---|---|
Processor | Ryzen 7 7700x PBO |
Motherboard | ASRock x670e Steel Legend |
Cooling | Noctua NH-D15 G2 LBC |
Memory | G.skill Trident Z5 Neo 6000@CL30 |
Video Card(s) | ASRock rx7900 GRE Steel Legend |
Storage | 2 x 2TB Samsung 990 pro nmve ssd 2 X 4TB Samsung 870 evo sata ssd 1 X 18TB WD Gold sata hdd |
Display(s) | LG 27GN750-B |
Case | Fractal Torrent |
Audio Device(s) | Klipsch promedia heritage 2.1 |
Power Supply | FSP Hydro TI 1000w |
Mouse | SteelSeries Prime+ |
Keyboard | Lenovo SK-8825 (L) |
Software | Windows 10 Enterprise LTSC 21H2 / Windows 11 Enterprise LTSC 24H2 with multiple flavors of VM |
System Name | KHR-1 |
---|---|
Processor | Ryzen 9 5900X |
Motherboard | ASRock B550 PG Velocita (UEFI-BIOS P3.40) |
Memory | 32 GB G.Skill RipJawsV F4-3200C16D-32GVR |
Video Card(s) | Sparkle Titan Arc A770 16 GB |
Storage | Western Digital Black SN850 1 TB NVMe SSD |
Display(s) | Alienware AW3423DWF OLED-ASRock PG27Q15R2A (backup) |
Case | Corsair 275R |
Audio Device(s) | Technics SA-EX140 receiver with Polk VT60 speakers |
Power Supply | eVGA Supernova G3 750W |
Mouse | Logitech G Pro (Hero) |
Software | Windows 11 Pro x64 23H2 |