Flamingo Raises $4.5M Seed Round

Skip to content

A pop-up at every boot says a driver cannot load, names a file nobody installed on purpose, and offers a Learn more button that explains the setting but not the file. The file belongs to the RGB lighting software that came with the motherboard, and Windows is right to refuse it. This guide explains what ene.sys is, why memory integrity blocks it, and how to clear the error without turning that protection off.

What ene.sys Is and Where It Came From

ene.sys is a kernel driver from ENE Technology Inc., a Taiwanese controller maker. It ships inside motherboard and peripheral lighting software, where it gives the RGB app direct access to the lighting controller on the board. Users who hit the pop-up trace it back to MSI Center and Mystic Light, ASUS Armoury Crate and Aura Sync, Gigabyte RGB Fusion, and the bundled utilities on prebuilt gaming PCs from iBUYPOWER and similar builders.

The driver stays behind when the app goes. One commenter on the r/computers thread below uninstalled RGB Fusion years earlier and still had ene.sys in the driver store, which is the usual shape of this problem: the app is gone or outdated, and the file it left in System32 is the version Windows now refuses.

The dialog comes from the Program Compatibility Assistant. As a user posted it to r/iBUYPOWER in 2023: "A driver cannot load on this device. Driver: ene.sys. A security setting is detecting this as a vulnerable driver and blocking it from loading." A named driver, a security setting, a block.

The replies on that October 2024 thread split in two. Rename the file to ene.sys.old and restart, or treat it as a driver package and let pnputil remove it. Both work. One of them stays fixed.

Why Windows Blocks It

Two Windows protections sit between a kernel driver and the kernel, and ene.sys fails both. The first is the Microsoft vulnerable driver blocklist, a signed policy of drivers Microsoft knows to have exploitable bugs, malware-signed certificates, or behaviour that gets around the Windows security model. Per Microsoft Learn (updated May 2026), the blocklist has been on by default since the Windows 11 2022 Update, is refreshed quarterly, and gets its updates through the monthly Windows updates. The current policy, version 10.0.29545.0 in the download Microsoft publishes, carries a signer-level deny for drivers signed under the Microsoft Windows Third Party Component CA for ENE Technology Inc., which is why the block ignores whatever version string the file reports.

The second protection is memory integrity, which Microsoft also calls hypervisor-protected code integrity (HVCI). It runs the code integrity checks inside a virtualized environment that a compromised kernel cannot reach, and it refuses any driver that fails those checks. Microsoft's Learn page (August 2026) says memory integrity is on by default on most new Windows 11 devices, and that the vulnerable driver blocklist is enforced whenever memory integrity, Smart App Control or S mode is active. Turn one of those on and the blocklist stops being optional.

ENE's driver landed on the list for the reason RGB drivers keep landing there. Lighting software wants to poke hardware registers directly, so its driver hands that access to any user-mode program that asks. The LOLDrivers project, which catalogues drivers abused in attacks, lists ene.sys with four known vulnerable file hashes, added in May 2023. That is a ladder from a normal user account into the kernel, so Windows treats a lighting helper the way it treats a rootkit loader.

The Fix That Keeps Memory Integrity On

The pop-up is a symptom. The problem is a vulnerable driver on the disk, so the fix is to replace it or remove it, in that order, and never to lower the setting that caught it.

Start with the app that installed the driver. Update the vendor utility (MSI Center, Armoury Crate, RGB Fusion or the prebuilt's own control panel), or uninstall it and install the current version from the manufacturer's support page. Current builds ship a driver that loads under memory integrity, and the Microsoft Q&A thread on this error ends with the poster fixing it by reinstalling the ASUS software. RGB keyboards and mice count too. Our guide on updating drivers covers the vendor-first order for everything else in Device Manager.

If the app is already gone and the driver is an orphan, remove the package from the driver store rather than the file from System32. Run an elevated prompt and list the third-party packages:

code
pnputil /enum-drivers

Find the entry whose Original Name or Provider mentions ENE and note its Published Name (oemNN.inf). Then delete it:

code
pnputil /delete-driver oemNN.inf /uninstall /force

Microsoft documents the /uninstall flag as removing the package from any device using it and /force as deleting it even when it is in use, both available since Windows 10 version 1607. Restart, and the Program Compatibility Assistant has nothing left to complain about. The walkthrough below shows the same steps on screen, including where the driver store entry hides:

Renaming C:\Windows\System32\drivers\ene.sys to ene.sys.old, the fix most Reddit threads land on, does clear the pop-up. It also leaves the package in the driver store, so the next vendor app repair, Windows Update driver sync or app reinstall can put the file straight back. Treat it as a stopgap for a machine you cannot touch properly today.

What you should not do is open Windows Security and switch memory integrity off. It stops the pop-up because it stops the check, so every other blocklisted driver on the machine gets a pass too. Microsoft's support page for this message does list turning the setting off as the fallback, with a warning attached; its Core isolation page (February 2026) puts the better options first: get an updated driver, or remove the device or app that uses it. Our post on Smart App Control makes the parallel point about the other switch people reach for.

How to Confirm the Driver Is Gone

Three places tell you whether the fix held, and none of them is the absence of a pop-up.

The first is the driver store. Run pnputil /enum-drivers again and confirm no ENE package remains. If the vendor app is still installed, you want one ENE package with a current date, not none; the app needs its driver, just a signed one.

The second is Windows Security. Under Device security, Core isolation, the memory integrity toggle shows a link to review incompatible drivers when something is blocking it. Per Microsoft Learn, Windows 11 22H2 and later also warn through the taskbar icon when the feature is off. Confirm the toggle is on and the list is empty. The msinfo32 System Summary names the virtualization-based security services running, and memory integrity should be among them.

The third is the event log, under Applications and Services Logs, Microsoft, Windows, CodeIntegrity, Operational. Per Microsoft's App Control event reference, 3077 is the main block event for an enforced policy, and 3033 appears when a file's signature fails the required signing level. A clean boot with no 3077 for ene.sys is the receipt.

The December 2025 thread above is the whole problem in one screenshot. Every reply says the same thing: update whatever RGB software is on the machine. One traced the file to RGB Fusion left behind after an uninstall, and the update removed it.

Across a Fleet

One gaming PC with a lighting app is a ten-minute job. Thirty workstations from a builder that preinstalled the RGB suite is a policy question: the same pop-up on every machine means the same vulnerable driver on every machine, and a technician who clears it by disabling memory integrity has lowered the security of the whole estate.

Set the policy first. Microsoft Learn (August 2026) lists four ways to enforce memory integrity: Windows Security, the Intune settings catalog or the VirtualizationBasedTechnology CSP, Group Policy under Computer Configuration, Administrative Templates, System, Device Guard, or the DeviceGuard registry keys. Pick "Enabled without UEFI lock" in Group Policy; the locked variant needs a trip to the firmware menu to ever turn off again. Memory integrity needs hardware virtualization on, so a fleet with it off in firmware needs that fixed first; our post on enabling virtualization in BIOS covers that at scale.

Then inventory the driver. This script reports whether memory integrity is running and whether an ENE driver package is present, so you can see how many machines need the app updated versus the orphan removed:

powershell
$dg = Get-CimInstance -Namespace root\Microsoft\Windows\DeviceGuard -ClassName Win32_DeviceGuard
$hvci = $dg.SecurityServicesRunning -contains 2
$ene = (pnputil /enum-drivers) -join "`n" -match '(?i)ene'
$file = Test-Path "$env:SystemRoot\System32\drivers\ene.sys"
[pscustomobject]@{ Host = $env:COMPUTERNAME; MemoryIntegrity = $hvci; EneInStore = $ene; EneFileOnDisk = $file }

OpenFrame can run a script like this across a client's devices and collect each machine's output, which turns the pop-up into a count. Machines where the lighting app is wanted get it updated; machines where nobody has opened it since the box arrived get the package removed and the app uninstalled with the rest of the preinstalled extras, the way our debloat guide handles them.

The last step is to stop the next one. The blocklist Microsoft ships denies hundreds of drivers from storage, anti-cheat, overclocking and hardware monitoring tools, not only lighting. If a client's fleet runs any of those, WDAC lets you apply the latest recommended block rules ahead of the quarterly refresh, and audit what would be blocked before you enforce it.

The Short Version

ene.sys is the ENE Technology lighting driver that MSI, ASUS, Gigabyte and prebuilt-PC utilities install. Microsoft's vulnerable driver blocklist denies it, memory integrity enforces that list, and Windows refuses it at boot. Update the RGB software or remove the orphaned package with pnputil, confirm with the driver store and the CodeIntegrity log, and leave memory integrity on. For what a bad driver does once it is loaded, read our post on the blue screen of death; for what an attacker does with a hole like this, start with what exploit means.

FAQ

Is ene.sys a virus?

No. It is a legitimately signed driver from ENE Technology that ships with RGB lighting software. Windows blocks it because the driver has known weaknesses that malware can use to reach the kernel, not because the file itself is malicious. A copy of ene.sys in a folder other than System32\drivers, or on a machine with no RGB hardware or software, is worth a closer look.

Can I just delete ene.sys from System32?

You can, and the pop-up will stop, but the driver package stays registered in the driver store and a vendor app repair or reinstall can put the file back. Removing the package with pnputil /delete-driver, or updating the app that owns it, is the fix that holds.

Will turning off memory integrity fix the ene.sys error?

It will hide it. Memory integrity is the protection that caught the driver, and switching it off also stops Windows from enforcing the vulnerable driver blocklist on that machine. Update or remove the driver instead, and keep the setting on.

Which programs install ene.sys?

Motherboard and peripheral lighting utilities: MSI Center and Mystic Light, ASUS Armoury Crate and Aura Sync, Gigabyte RGB Fusion, and the control software bundled with prebuilt gaming PCs. Current versions of these utilities ship an updated driver. If none of them is installed and the file is still there, it is a leftover from an earlier uninstall.

Dmytro Koval

Dmytro Koval

Head of Product Engineering

Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

ene.sys Driver Cannot Load

No. It is a legitimately signed driver from ENE Technology that ships with RGB lighting software. Windows blocks it because the driver has known weaknesses that malware can use to reach the kernel, not because the file itself is malicious. A copy of ene.sys in a folder other than System32\drivers, or on a machine with no RGB hardware or software, is worth a closer look.
You can, and the pop-up will stop, but the driver package stays registered in the driver store and a vendor app repair or reinstall can put the file back. Removing the package with pnputil /delete-driver, or updating the app that owns it, is the fix that holds.
It will hide it. Memory integrity is the protection that caught the driver, and switching it off also stops Windows from enforcing the vulnerable driver blocklist on that machine. Update or remove the driver instead, and keep the setting on.
Motherboard and peripheral lighting utilities: MSI Center and Mystic Light, ASUS Armoury Crate and Aura Sync, Gigabyte RGB Fusion, and the control software bundled with prebuilt gaming PCs. Current versions of these utilities ship an updated driver. If none of them is installed and the file is still there, it is a leftover from an earlier uninstall.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.