HeadlinesBriefing favicon HeadlinesBriefing.com

HWMonitor 1.63 Download Turns Out to Be Malware, Even from Trusted Site

Hacker News •
×

After years of using HWMonitor, a user triggered an automatic update to 1.63 from the official cpuid site. The installer, named HWiNFO_Monitor_Setup.exe, activated Windows Defender immediately, flagging it as a virus. The user dismissed the alert, ran the file, and a Russian‑styled installer appeared.

VirusTotal analysis returned a clean bill of health for the downloaded 1.63 file, yet the author reports a Russian install program popping up. A friend supplied a 1.61 build that also cleared scans. Attempts to pull 1.62 failed, producing a generic hwmonitor_1.62.exe that redirected to the 1.63 executable, confirming the link’s validity in for users.

Despite the clean scans, the experience underscores that even trusted sites can host malicious payloads. The incident prompted the user to avoid submitting personal data via the cpuid contact form, citing reluctance after the scare. It raises questions about the integrity of the download process and the need for stricter verification mechanisms in software distribution.

Users relying on HWMonitor should verify file hashes against those listed on cpuid’s official page before installing. Maintaining an up‑to‑date antivirus and checking VirusTotal can help, but this case shows that even a clean scan does not guarantee safety. Administrators must enforce strict download policies to safeguard systems from disguised malware in production environments daily.