Rivon. How to remove? (Uninstall guide)

removal by Jake Doevan - -   Also known as Attech | Type: Worms
12

Rivon, also known as Attech, is an Internet worm, which spreads by e-mail and through file sharing networks. It usually arrives in infected executable files attached to bogus e-mail messages. The user can also download the parasite as a purportedly useful program using a peer-to-peer application.

Once executed, Rivon installs itself to the system and runs a spreading routine. The worm copies itself to floppy disks, creates infected files with meaningful names in shared folders of installed instant messengers and file sharing clients including eDoneky2000, eMule, Kazaa, Morpheus, Grokster, iMesh, LimeWire, Kmd and ICQ. Rivon also searches local files for e-mail addresses, collects them and sends out malicious letters. E-mail messages have one of the following subjects:
“Buf Fix For NOD32”, “Microsoft SP2”, “New worms”, “Save”, “Test The New Sophos Anti-Virus”
and one of the following bodies:
“In the attachment we send you the new version of NOD32 Patch”
“Microsoft have release SP2, run the attechment and it will download SP2 To you”
“If you have (or if you think) that you have on your PC undetected virus/worm then run the progi in the attechment.”
“Save the file on your disk!”
“I send to you the test Sophos AV”

The parasite’s payload is comprised of several harmful functions. Rivon changes Windows Explorer and Internet Explorer default settings, disables numerous system components, blocks access to system configuration utilities, modifies keyboard and mouse settings, hides the desktop and clock, etc. The worm terminates running antiviruses, firewalls and various security-related software. It also blocks access to popular security-related web sites.

Rivon automatically runs on every Windows startup.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Rivon you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Rivon. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

More information about this program can be found in Reimage review.

Rivon manual removal:

Kill processes:
cro.exe,download.exe,kaspersky_lab.exe,matrix.exe,nod32_fix.exe,rj3_vc1.exe,save_me.exe,sophos_3.89.exe,speed.exe,sp2.exe

Delete registry values:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRundownload

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMainShowGoButton=no

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun1=services.msc

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun2=gpedit.msc

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun3=msconfig.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun4=secpol.msc

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun5=sysedit.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun6=cmd.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun7=mmc.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun8=progman.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun9=ntbackup.exe

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerDisallowRun10=rsop.msc

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerHideClock=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoBandCustomize=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoCDBurning=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoChangeStartMenu=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoClose=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoControlPanel=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoDisconnect=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFileMenu=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFind=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFolderOptions=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoNetworkConnections=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoPropertiesMyComputer=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoSetTaskbar=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoSharedDocuments=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoSMHelp=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoSMMyDocs=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoSMMyMusic=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoSMMyPictures=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRecentDocsMenu=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoStartMenuMFUprogramsList=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoStartMenuMoreProgram=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoStartMenuNetworkPlaces=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoUserNameInStartMenu=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoViewContextMenu=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoWindowsUpdate=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoWinKeys=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoAdminPage=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoDevMgrPage=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoDispScrSavPage=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoDispSettingsPage=1

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoProfilePage=1

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictionsNoBrowserClose=1

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictionsNoBrowserOptions=1

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictionsNoFileNew=1

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictionsNoFileOpen=1

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictionsNoFindFiles=1

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictionsNoSelectDownloadDir=1

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorerNoDesktop=1

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindows NTSystemRestoreDisableSR=1

Delete files:
cro.exe,download.exe,kaspersky_lab.exe,matrix.exe,nod32_fix.exe,rj3_vc1.exe,save_me.exe,sophos_3.89.exe,speed.exe,sp2.exe

About the author

Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

More information about the author