Jump to content

WinRing0

I was clearing out some files on my hard drive the other day, and came across a file labeled WinRing0. I don't remember anything relating to it, and I can't find anything about it online. Anyone know what it is? And if it's malicious, how to remove it?

 

Screenshot (4).png

Screenshot (5).png

Link to comment
Share on other sites

Link to post
Share on other sites

welcoem to the Linus Tech Tips forums!

 

it is a support folder for razor products.

some malware camouflages itself as winring0.sys. you should check the winring0.sys process on your PC to see if it is a threat.

Link to comment
Share on other sites

Link to post
Share on other sites

I'm currently running a malwarebytes rootkit/system scan, and so far nothing has come up. Any way to safely delete it?

 

 

Update: I'm looking at the dates that it was downloaded, and it seems to match up with my EVGA PrecisionXOC download. Do you think it would have come with the EVGA software?

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

You can check this by yourself - right mouse button, locate file and maybe you'll find your answer. Also - use Autoruns.

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, homeap5 said:

You can check this by yourself - right mouse button, locate file and maybe you'll find your answer. Also - use Autoruns.

I ended up deleting the file and everything relating to it, running Malwarebytes to make sure it was all clear just Incase, and everything that I assumed could be in trouble ended up working just fine. So either way, if it was malicious, I’m a little safer, and if not, it didn’t really affect anything.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×