Hidexls manual removal:
Kill processes:
data uang.exe, excel optimise.exe, isassi.exe, keuangan.exe, system32.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\mymoney
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\systemregistry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\systrays
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mymoney
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\systemregistry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\systrays
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=%System%\isassi.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell=%System%\isassi.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\AlternateShell=%System%\isassi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoTrayContextMenu=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun=1
Delete files:data uang.exe, excel optimise.exe, isassi.exe, keuangan.exe, system32.exe, msvbvm60.dll, autoexec.bat
Delete directories:C:\WINDOWS\System32\Systim
C:\WINNT\System32\Systim
C:\WINDOWS\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}
C:\WINNT\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}
Misc:Exact file location:
system32.exe - C:\WINDOWS\System or C:\WINNT\System
isassi.exe - C:\WINDOWS\System32 or C:\WINNT\System32
autoexec.bat - C:\Documents and Settings\[Current User]\Favorites
keuangan.exe - C:\Documents and Settings\[Current User]\My Documents
data uang.exe, excel optimise.exe - C:\Documents and Settings\[Current User]\Start Menu\Programs\Startup
msvbvm60.dll - C:\WINDOWS\System32\Systim or C:\WINNT\System32\Systim; C:\WINDOWS\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\System or C:\WINNT\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\System