RingZero.Trojan - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: October 26, 1999
Updated: February 13, 2007 11:54:35 AM
Also Known As: RingZero.gen Trojan, Trojan.Rhino
Type: Trojan Horse


To remove this Trojan, delete files detected as RingZero.Trojan, and remove references from the \Run key.

To delete the files:
  1. Run LiveUpdate to make sure that you have the most recent virus definitions.
  2. Start Norton AntiVirus (NAV), and run a full system scan, making sure that NAV is set to scan all files.
  3. Delete any files detected as RingZero.Trojan. If NAV is not able to delete the files, do the following:
    1. Write down the names and locations of the files that NAV detected.
    2. Restart the computer in MS-DOS mode, or boot to a clean DOS boot floppy disk.
    3. Delete the detected files from the \Windows\System folder.
    4. Delete the Its.dat and Ring0.dat files from the \Windows\System folder.
    5. Restart Windows.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before making any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure you modify only the keys specified. Please see the document How to back up the Windows registry before proceeding.
  1. Click Start, and click Run. The Run dialog box appears.
  2. Type regedit and then click OK. The Registry Editor opens.
  3. Navigate to the following key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  4. In the right pane, look for the following values, and if found, delete them:

    DK32 support PST "pst.exe"
    DK32 support ITS "its.exe"
    Description of EPS II "telnet23.exe"


Writeup By: Wason Han
Search by name
Example: W32.Beagle.AG@mm
Limited Time Offers! Save up to 50%
Windows Vista Security