•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  just4fun
RegRun Security Suite
Not an antivirus. Detects and removes rootkits/malware/adware that your antivirus could not.
One-click purchase
RegRun NIVA Platinum - Rootkit Killer


More info:
Know more?


On-line manual

Print PDF

Download trial
RegRun NIVA Platinum
Greatis Forum

NI Forum

Mickey Forum

Thank you!

Download Russian

Download Ukrainian

Join our localization team

Home Download Order Support   Newsletter Your shopping cart ?
Virus Removal Story: ntsystem.exe, ntoskrnl.dll, gviz

This detective story begins with usual support request from a one of RegRun's users.

Greatis Software support expert detected suspicious file in the user's system report file. This file is generated by free Greatis Software Reanimator software.

It was the "c:\windows\system32\ntsystem.exe". This file was registered in the "Run" startup keys as "gwiz".

But deletion of the "ntsystem.exe" file doesn't not provide us any success. The file is automatically recreated after reboot. Catty tried to delete "ntsystem.exe" at Windows restart using the newest Greatis Software product called "Partizan". Partizan doesn't use Windows "PendingFileRename key for deleting. It uses own Native API application and Partizan successfully deleted "ntsystem.exe".

But after successful Windows loading we got "ntsystem.exe" again.

Catty asked a user for getting "xpbootlog.txt" report made by Greatis Software Bootlog XP tool. We analyzed received "xpbootlog.txt" and found the strange file: NTOSKRNL.DLL.

It looks like the Windows related system file. NTOSKRNL.EXE is a good known Windows system file. But NTOSKRNL.DLL is not the same.

After that we opened xpbootlog.txt using Bootlog XP software.

We found that the DLL was loaded by Winlogon. NTOSKRNL.DLL is registered as Winlogon Notification DLL.

NTOSKRNL.DLL is a user mode rootkit. It hides its presence in the registry and in the loaded modules listing.

You could not delete it using standard Windows deletion methods.

Removal Instructions

  1. Download our special software:
    RegRun Reanimator
    Unzip it to any folder on your hard drive.
  2. Open Reanimator.exe. Open "Reanimator" menu, "Execute Reanimator Job". Choose "ntsystem.rnr" file. "NTSYSTEM.RNR" job contains the procedure for activating RegRun Partizan and deleting the ntsystem.exe and ntoskrnl.dll at reboot.

    You will see the "RegRun Partizan" on the Windows blue boot screen in the same moment when Windows checking hard drives.

    Look at the messages on the screen to be sure that the dangerous files are deleted.

  3. Restart your computer. Open Reanimator and choose "Scan for Viruses" to be sure that it is complete.
  4. Visit our Support center if you have any questions.
    Open a support ticket and attach your detailed system report made by RegRun Reanimator.
  5. To remove Partizan from your computer, open Reanimator.exe, go to the "Features", "Partizan".
    Click on the "Remove" button.


Suggest you to use RegRun Platinum Edition to be sure that your rootkit's clear!

Good luck!

Dmitry Sokolov


I am a senior citizen who is trying to learn as much as I can about computers in my retirement. On September 6, 2006 I received a NTSYSTEM.EXE file that I could not delete, caused numerous popups on my computer, and caused me great concern and four (4) full days of research before seeing your website offering a solution to the problem. Keep in mind I have Dell, Microsoft and McAfee security measures in operation on my computer. You suggest that people infected with the above malicious file download and run your RegRun Animator. I took your suggestion. To my great surprise and pleasure, the associated files were gone in a matter of minutes. Not only that, your RegRun Animator helped me delete other unwanted files. My hats off to you. I can now go about the business for which I bought my computer without interruption. Thank you, and thank you again.

Jack Nelson

What's new?

June 5 2013

Released RegRun Security Suite
Full version is available for download.
Update is free for registered users

Released RegRun Reanimator - free software for detecting and removing rootkits & malware.

April 19 2013

Released RegRun Security Suite
Full version is available for download.
Update is free for registered users

Released RegRun Reanimator - free software for detecting and removing rootkits & malware.

March 6 2013

Released RegRun Security Suite
Full version is available for download.
Update is free for registered users

Released RegRun Reanimator - free software for detecting and removing rootkits & malware.

September 10 2012

BootRescue - free software for Master BootRecord (MBR)/Volume Boot Record (VBR) backup/recovery.

All News

RegRun is able to remove TDL 4 rootkit (MBR infector) on the Windows 32 and 64 bit!

Released Shortcut Antivirus is a free of charge software for protecting against Microsoft LNK vulnerability.

Released Stuxnet Remover is a free of charge tool for Stuxnet/Tmphider rootkit removal

Added detection and removal of Stuxnet Rootkit(mrxnet.sys, mrxcls.sys).

Resolve "Google search redirect problem". Remove TDL3+ rootkit now!

How to resolve the "msls52.dll not found" problem.
New attack against UXTHEME.DLL...

How to resolve the "themed32.dll not found" problem...

Use RegRun Warrior for rootkit removal
Rootkit detection and removal takes 10 minutes with one computer reboot!

Be careful! The QVOD player installer may be a Trojan...

New! Examiner reveals hidden rootkits and infected system drivers!

New Porno banner Troan Oficla removal instructions

TDSS/Alureon removal instructions

Resolving problem with Google redirect MAX++/TDSS rootkit (win32k.sys:1, win3k.sys:2).

Video Lesson how to remove WinLocker Trojan

Malware Removal Lesson

Windows Explorer Redirection DLLS is a new dangerous Windows startup hole...

RegRun has been reviewed by Software Directory: RegRun Security Suite is an excellent tool that will reliably protect your computer from a plethora of existing and emerging threats and will keep malware at bay.

Removing Medichi Rootkit

Removal of Noskrnl.exe and Noskrnl.sys Rootkit (Spooldr clone)

Removal Baidu rootkit (cnprov.sys)

Removal Spooldr(ecard.exe) rootkit

Fixing BSOD
in Winlogon Process

Removal Areses Trojan

Virus Feebs rootkit removal story

What's this? Rthdcpl.exe - Illegal System DLL Relocation...

Warning! Rootkit Unhooker

Read our article about Unreal rootkit...

Released free Rustock Rootkit(lzx32.sys) removal tool

A#######.sys is a rootkit?

Rootkit Removal instructions: ntsystem.exe

What is BDGuard.sys?

Virus or not? SPTD####.sys

What is mc21.tmp, mc22.tmp, mc23.tmp?

ICQCHK.exe, MSX.DLL free remover...

Ask Computer Guys

Windows startup programs

Using Registry Tracer...

RegRun against Trojans and Viruses

Specify an order for startup programs

RunGuard prevents a launch...

Using Bootlog Analyser...

They say
"RegRun Security Suite is one of those very rare tool kits that no one who is serious about protecting their PC should ever be without. This toolkit covers all the bases when it comes to eradicating the attempted security threats from malware that we all face - daily. The near real time tech support, direct from Greatis, is nothing sort of superb, something that can be rarely said these days! I have no hesitation in recommending this suite to anyone."

Miles Pearson

Wilders.ORG. Security advisors recommend...

You guys are awesome!!!!

Bob Schmulian:
Absolutely love it and have recommended to many people!

Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since I purchased it less than 6 months ago. I now would not run my system without it... it's worth many times the cost! The service and support are terrific. Helpful - friendly - and accommodating; and generally a reply is received within 12 hours. Just great.

Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.

Paul's Picks
Shareware Winner  


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | just4fun

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2013 Greatis Software

hit counter for tumblr