Skip to main content
All legal documents
Switch document

WinGauge Hardware Monitor Driver

Last updated August 18, 2026

What this document covers

This notice describes the WinGauge Hardware Monitor driver, published by MudCrab Labs as part of the WinGauge PC monitoring app. Its file name is wghwmon.sys, short for WinGauge Hardware Monitor, and it is the only kernel-mode component MudCrab Labs installs on any customer machine. Nothing else in our catalogue installs a kernel driver.

This document is incorporated by reference into our Terms of Service and our License Agreement. By installing WinGauge and consenting to its driver installation prompt, you accept the terms below.

What the driver is

wghwmon.sys is a small Windows kernel driver written to the Kernel-Mode Driver Framework (KMDF). It exposes a fixed, whitelisted IOCTL surface that user-mode WinGauge uses to read low-level hardware sensors that ordinary applications cannot reach on their own: CPU package temperature and power, per-core effective clocks, and a handful of motherboard fan tach and voltage signals when the board exposes them.

The driver is optional. WinGauge starts, runs, and displays readings without it. When the driver is not installed, WinGauge falls back to Windows Management Instrumentation (WMI) and vendor SDKs (for example NVML on NVIDIA GPUs), and simply omits any reading that requires kernel access.

Publisher and signature

wghwmon.sys is published by MudCrab Labs. The file carries a valid Windows Authenticode signature. Right-click the file in Windows Explorer, choose Properties, and open the Digital Signatures tab to confirm the signer reads MudCrab Labs. A driver whose signature does not match should not be trusted and should not be loaded.

The signed driver loads on 64-bit Windows 10 and Windows 11.

Installation

The driver is installed on demand from within WinGauge, or automatically during the WinGauge installer. Installation calls Windows' built-in Service Control Manager (sc.exe) with the driver payload that ships in the WinGauge program folder to create a kernel service named 'wghwmon' and start it. Because creating a kernel service is a privileged operation, Windows will show a standard User Account Control (UAC) elevation prompt; nothing installs without your click.

The driver is loaded only while WinGauge asks Windows to start the service. You can stop it at any time without uninstalling WinGauge by running 'sc stop wghwmon' from an elevated command prompt.

What the driver reads

The driver's IOCTL surface is fixed and limited. It exposes: a version query; a set of whitelisted Model-Specific Register (MSR) reads for CPU temperature, power, and effective performance counters that the CPU vendor documents as safe to read; and a wrapper over Windows' own thermal-zone and fan interfaces (MSAcpi_ThermalZoneTemperature, board-supplied fan controllers). It does not accept arbitrary MSR reads, arbitrary port I/O, or arbitrary memory access from user mode.

The driver never writes to hardware. It performs read-only queries against the sensors above and hands the numeric results back to user-mode WinGauge, which draws them on screen.

What the driver collects

Nothing. wghwmon.sys performs local reads only. It does not open network sockets. It does not collect telemetry. It does not log to disk. It does not persist any part of what it reads. Sensor values live in memory long enough for WinGauge to display them and then are discarded.

Any network traffic you see attributed to WinGauge is the optional user-mode update check, subject to our Privacy Policy. The driver itself is not part of that traffic.

Risk profile and your consent

Any Windows kernel driver, including this one, runs at Ring 0 and can in principle affect system stability if it contains a defect. We have engineered wghwmon.sys to a small, fixed surface, tested it on the Windows versions we support, and shipped it under a code-signing certificate that Microsoft can, and does, revoke if a driver misbehaves. We nonetheless disclose the general risk of any kernel-mode software so you can make an informed choice.

By clicking through the UAC elevation prompt at install time, you consent to the driver being created as a kernel service and to it running when WinGauge starts it. You may withdraw that consent at any time by removing the driver as described below.

Removing the driver

Uninstalling WinGauge through Windows Settings > Apps removes wghwmon.sys as part of the standard uninstall.

To remove the driver alone while keeping WinGauge, open an elevated command prompt (or Windows Terminal running as Administrator) and run 'sc stop wghwmon' followed by 'sc delete wghwmon'. The service is removed, and WinGauge falls back to its user-mode monitoring paths on the next launch.

There is no additional cleanup step and no leftover registry hive beyond the service registration, which is removed by the 'sc delete' step above.

Antivirus and false positives

A small number of antivirus products occasionally flag kernel-mode monitoring drivers on heuristic signal alone. The signed wghwmon.sys shipped with WinGauge is safe. If you see a warning, verify the file's Authenticode signature reads MudCrab Labs, then either trust the file in your antivirus's user interface or open a support ticket at support@mudcrab.co with the vendor and detection name so we can request a re-scan.

Legal position

Notwithstanding anything in this document, MudCrab Labs' aggregate liability for the driver is limited as set out in our Terms of Service and License Agreement, and the disclaimers of warranty in those documents apply in full to the driver. You install and use the driver at your own risk.

Questions about these terms?

Contact us