Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Rivarts.A


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Rivarts.A
Reply
 
Thread Tools
Old 27-03-2006, 11:48   #1
cf.geek
 
Join Date: Dec 2003
Location: Coventry
Posts: 518
banjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of light
Rivarts.A

Hi,
Windows defender keeps detecting and deleting "Rivarts.A" a key logger.

Everytime I reboot this malware is detected again and I have to delete it, I have tried surches on google and yahoo and even with their information I cannot stop this virus from re-instaling itself.

I have a firewall and anti virus software including Spyware Doctor, any ideas, thanks.
banjo is offline   Reply With Quote
Old 27-03-2006, 11:56   #2
cf.geek
 
Tightscot's Avatar
 
Join Date: Sep 2003
Location: Location Location...
Posts: 648
Tightscot has reached the bronze age
Tightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze age
Re: Rivarts.A

have you tried running 'msconfig' and checking through the startup items?

also if running Win XP with system restore turned on, then you'll need to turn it off - thus deleting the restore points (which may contain the virus) then rebooting and turning System restore back on...

Last edited by Tightscot; 27-03-2006 at 12:01.
Tightscot is offline   Reply With Quote
Old 27-03-2006, 12:02   #3
cf.geek
 
Join Date: Dec 2003
Location: Coventry
Posts: 518
banjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of light
Re: Rivarts.A

Quote:
Originally Posted by Tightscot
have you tried running 'msconfig' and checking through the startup items?
Yes, but what I have learned about this virus is that it "shields" itself from detection and can be delivered by another programme so I do not know what to look for ? Thank you for your reply
banjo is offline   Reply With Quote
Old 27-03-2006, 12:03   #4
cf.geek
 
Tightscot's Avatar
 
Join Date: Sep 2003
Location: Location Location...
Posts: 648
Tightscot has reached the bronze age
Tightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze age
Re: Rivarts.A

what anti virus software do you use? and is it up to date?
Tightscot is offline   Reply With Quote
Old 27-03-2006, 12:08   #5
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Rivarts.A

First, you need to disable System Restore. Follow the instructions at http://www.pchell.com/virus/systemrestore.shtml

Then, to remove it. Your virus scanner (or Windows Defender) should be able to remove it. Check the removal instructios at http://www.pandasoftware.com/virus_i...&idvirus=92688

Now, re-enable System Restore. The Disabling/re-enabling of System Restore is important as System Restore will sometimes back up viruses, then stop the virus scanner deleting the virus from the backup, so the virus gets restored next time System Restore is run.
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 27-03-2006, 12:10   #6
cf.geek
 
Join Date: Dec 2003
Location: Coventry
Posts: 518
banjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of light
Re: Rivarts.A

Quote:
Originally Posted by Tightscot
what anti virus software do you use? and is it up to date?
AVG free, Spyware Doctor, and a firewall and yes all is up to date, I have looked at the spyware definitions on AVG and Spyware Doctor and neither of them mentions Rivarts.A ?
banjo is offline   Reply With Quote
Old 27-03-2006, 12:16   #7
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Rivarts.A

Also, in terms of Anti Spyware, I would recommend Spybot , as well as AdAware and Spyware Blaster
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 27-03-2006, 12:19   #8
cf.geek
 
Join Date: Dec 2003
Location: Coventry
Posts: 518
banjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of light
Re: Rivarts.A

Quote:
Originally Posted by Stuart C
First, you need to disable System Restore. Follow the instructions at http://www.pchell.com/virus/systemrestore.shtml

Then, to remove it. Your virus scanner (or Windows Defender) should be able to remove it. Check the removal instructions at http://www.pandasoftware.com/virus_i...&idvirus=92688

Now, re-enable System Restore. The Disabling/re-enabling of System Restore is important as System Restore will sometimes back up viruses, then stop the virus scanner deleting the virus from the backup, so the virus gets restored next time System Restore is run.
I have been to this site and tried their suggestions but it still re-installs itself after each re-boot !
banjo is offline   Reply With Quote
Old 27-03-2006, 12:25   #9
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Rivarts.A

Did you do the following?

Quote:

How to remove Rivarts.A?

If Panda Antivirus or Panda ActiveScan detects Rivarts.A during the scan, it will automatically offer you the option of deleting it. Do this by following the program's instructions.
Finally, restore the original configuration of your computer by following the instructions below:
Delete the entry that Rivarts.A has created in the Windows Registry:
HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
Zsys = %sysdir%\ zsys.exe
where %sysdir% is the Windows system directory.
Restart the computer.
In order to make sure that Rivarts.A is completely eliminated from your computer, carry out a full scan of your computer using Panda Antivirus or Panda ActiveScan.

__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 27-03-2006, 12:26   #10
cf.geek
 
Tightscot's Avatar
 
Join Date: Sep 2003
Location: Location Location...
Posts: 648
Tightscot has reached the bronze age
Tightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze age
Re: Rivarts.A

What about going into msconfig, and turning off everything in the 'startup' section. Then reboot , turning each item back on, one at a time and checking to see if it reinstalls itself. that way you can find what startup entry is causing the reinstall.

Might take a while but may be the best way forward....
Tightscot is offline   Reply With Quote
Old 27-03-2006, 12:58   #11
cf.geek
 
Join Date: Dec 2003
Location: Coventry
Posts: 518
banjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of light
Re: Rivarts.A

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
Zsys = %sysdir%\ zsys.exe
where %sysdir% is the Windows system directory

Stuart, do I have to only delete %sysdir% as I cannot find this exact string, I have just down loaded and ran Ad-aware it found 15 problems but on re-boot the nasty was back, how come only Windows defender is the only spy ware programmer to detect it ? I have the other utilities you mentioned but they cannot deal with this problem either !

---------- Post added at 12:58 ---------- Previous post was at 12:56 ----------

Quote:
Originally Posted by Tightscot
What about going into msconfig, and turning off everything in the 'startup' section. Then reboot , turning each item back on, one at a time and checking to see if it reinstalls itself. that way you can find what startup entry is causing the reinstall.

Might take a while but may be the best way forward....
Thank you for that if all else fails I will have to go down that route !
banjo is offline   Reply With Quote
Old 27-03-2006, 13:16   #12
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Rivarts.A

Don't delete %sysdir% (either in the registry or on your drive). It is the folder that contains most of Windows System files, so even assuming Windows will allow you to delete it, you will disable Windows if you delete the whole folder.

The string should be "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows\CurrentVersion\Run\Zsys = %sysdir%\sys.exe"
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 27-03-2006, 13:17   #13
cf.geek
 
Tightscot's Avatar
 
Join Date: Sep 2003
Location: Location Location...
Posts: 648
Tightscot has reached the bronze age
Tightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze ageTightscot has reached the bronze age
Re: Rivarts.A

just to confirm you have done the following?

turn off system restore.

reboot system. and clear down all temp internet files etc

remove the virus.

reboot the system. - check virus has gone. if it has then:

tun system restore back on.

If it hasn't then see my last post!
Tightscot is offline   Reply With Quote
Old 27-03-2006, 13:20   #14
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: Rivarts.A

Exactly what I was trying to say..
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 27-03-2006, 13:21   #15
cf.geek
 
Join Date: Dec 2003
Location: Coventry
Posts: 518
banjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of lightbanjo is a glorious beacon of light
Re: Rivarts.A

Stuart C, I cannot find this "Zsys = %sysdir%\ zsys.exe" in the registry, I have looked and searched for this with no joy ?
banjo is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 12:27.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)