Rivarts manual removal:
Kill processes:
wscntfy.exe, zsys.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zsys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mchinjdrv
Delete files:wscntfy.exe, zsys.exe, zsys1.dll, zsys2.dll, mc[X].tmp, zsys2.db
Misc:[X] is a randomly chosen name or a combination of random characters.
The zsys2.db file contains stolen data.
Exact file location:
wscntfy.exe - C:\Windows or C:\Winnt
mc[X].tmp - C:\Windows\Temp or C:\Winnt\Temp
zsys.exe, zsys1.dll, zsys2.dll, zsys2.db - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: