Rivarts manual removal:
Kill processes:
wscntfy.exe, zsys.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zsys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mchinjdrv
Delete files:wscntfy.exe, zsys.exe, zsys1.dll, zsys2.dll, mc[X].tmp, zsys2.db
Misc:[X] is a randomly chosen name or a combination of random characters.
The zsys2.db file contains stolen data.
Exact file location:
wscntfy.exe - C:\Windows or C:\Winnt
mc[X].tmp - C:\Windows\Temp or C:\Winnt\Temp
zsys.exe, zsys1.dll, zsys2.dll, zsys2.db - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment:
Attention: Use this form only if you have additional information about Rivarts parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.