Jump to content
View in the app

A better way to browse. Learn more.

Pulseway

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

PulseWay Deploy detected an blocked by Microsoft Defender as 'Vigorf'

Posted

This is the report from Microsoft defender:



An active 'Vigorf' malware was blocked

New

Detected

Low

10/27/2025

3:33:33 PM

[17044] PCMonitorSrv.exe created file

PCMonitorSrv.sys

Malware

3:33:33 PM

[4] ntoskrnl.exe loaded image

PCMonitorSrv.sys

Malware

SHA1

d25340ae8e92a6d29f599fef426a2bc1b5217299

Path

C:\Program Files\Pulseway\PCMonitorSrv.sys

Size

14 KB

Is PE

True

Last modified time

Oct 27, 2025 3:33:33 PM

Initiating process

[4]

ntoskrnl.exe

Process id

4

Execution details

Token elevation: Default, Integrity level: System

Image file path

C:\Windows\System32\ntoskrnl.exe

Image file SHA1

d50cebb81fe449e0d62a4ae92b185b917e898eef

Image file creation time

May 12, 2025 7:48:05 AM

Image file last modification time

May 12, 2025 7:48:06 AM

PE metadata

ntoskrnl.exe

User

NT AUTHORITY\SYSTEM

PE metadata

PCMonitorSrv.sys

Original name

WinRing0.sys

Compilation timestamp

Jul 26, 2008 4:29:37 PM

Company

OpenLibSys.org

Product

WinRing0

Version

1.2.0.5

Description

WinRing0

Remediation details

Defender detected 'Trojan:Win32/Vigorf.A' in file 'PCMonitorSrv.sys', during attempted open by 'ntoskrnl.exe'

Malware

Is runtime packed

False

Threat name

Trojan:Win32/Vigorf.A

Remediation action

quarantine

Remediation action result

Fail

Detection time

Oct 27, 2025 3:34:05 PM

3:34:05 PM

ntoskrnl.exe interacted with file

PCMonitorSrv.sys

Malware

SHA1

d25340ae8e92a6d29f599fef426a2bc1b5217299

Path

C:\Program Files\Pulseway\PCMonitorSrv.sys

Size

14 KB

Is PE

True

Creation time

Oct 27, 2025 3:33:33 PM

Last modified time

Oct 27, 2025 3:33:33 PM

Initiating process

[4]

ntoskrnl.exe

Process id

4

Execution details

Token elevation: Default, Integrity level: System

Image file path

C:\Windows\System32\ntoskrnl.exe

Image file SHA1

d50cebb81fe449e0d62a4ae92b185b917e898eef

Image file creation time

May 12, 2025 7:48:05 AM

Image file last modification time

May 12, 2025 7:48:06 AM

PE metadata

ntoskrnl.exe

User

NT AUTHORITY\SYSTEM

PE metadata

PCMonitorSrv.sys

Original name

WinRing0.sys

Compilation timestamp

Jul 26, 2008 4:29:37 PM

Company

OpenLibSys.org

Product

WinRing0

Version

1.2.0.5

Description

WinRing0

Remediation details

Defender detected 'Trojan:Win32/Vigorf.A' in file 'PCMonitorSrv.sys', during attempted open by 'ntoskrnl.exe'

Malware

3:34:05 PM

PCMonitorSrv.sys

Malware

SHA1

d25340ae8e92a6d29f599fef426a2bc1b5217299

Path

C:\Program Files\Pulseway\PCMonitorSrv.sys

Size

14 KB

Is PE

True

Creation time

Oct 27, 2025 3:33:33 PM

Last modified time

Oct 27, 2025 3:33:33 PM

Signer

Noriyuki MIYAZAKI

Issuer

GlobalSign ObjectSign CA

VirusTotal detection ratio

4/72

Initiating process

Additional related files

PE metadata

PCMonitorSrv.sys

Original name

WinRing0.sys

Compilation timestamp

Jul 26, 2008 4:29:37 PM

Company

OpenLibSys.org

Product

WinRing0

Version

1.2.0.5

Description

WinRing0

Remediation details

Defender detected 'Trojan:Win32/Vigorf.A' in file 'PCMonitorSrv.sys', during attempted open by 'ntoskrnl.exe'

Malware

Is runtime packed

False

Threat name

Trojan:Win32/Vigorf.A

Remediation action

quarantine

Remediation action result

Fail

Detection time

Oct 27, 2025 3:34:05 PM



We are having this issue on multiple workstations where the deployment was done.

Featured Replies

  • Administrators

Hello,

This is happening due to a library we're using for hardware monitoring. We are in-progress of switching to a separate library in early 2026. The risk is related to a driver called WinRing0 which can be exploited to run arbitrary kernel-code. The driver on it's own will not cause a security problem.

-Paul

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.