Remove Hiween. Description and removal instructions

 
Title: Hiween

Type: Trojans
Severity scale:Hiween severity is 54  (54 / 100)
 
Hiween is a trojan that disables antiviruses and popular security-related programs. The parasite also terminates running web browsers and system utilities. Furthermore, it modifies numerous system settings disabling essential Windows functions, services (System Restore) and tools (Command Prompt, Task Manager, Registry Editor). Hiween creates multiple copies of itself. The trojan runs on every Windows startup and every time the user executes certain programs or opens specific files.


Related files: csrss.exe, iexplorer.exe, lsass.exe, mig2.exe, services.exe, shell.exe, smss.exe, winlogon.exe, mrhelloween.scr, empty.pif

Hiween properties:
• Hides from the user
• Stays resident in background

Automatic Hiween removal:

remover for Hiween

Hiween manual removal:

Kill processes:
csrss.exe, iexplorer.exe, lsass.exe, mig2.exe, services.exe, shell.exe, smss.exe, winlogon.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\logon [X]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mig2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msmsgs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services [X]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %System%\iexplorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%System%\iexplorer.exe
HKEY_CLASSES_ROOT\batfile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_CLASSES_ROOT\piffile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_CLASSES_ROOT\exefile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_CLASSES_ROOT\lnkfile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=%Windir%\mig2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger=%System%\shell.exe
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe=%System%\mrhell~.scr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\SystemRestore\DisableConfig=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\DisableMSI=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\LimitSystemRestoreCheckpointing=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\FullPathAddress=1
Delete files:
csrss.exe, iexplorer.exe, lsass.exe, mig2.exe, services.exe, shell.exe, smss.exe, winlogon.exe, mrhelloween.scr, empty.pif
Misc:
[X] is the current user name.

Exact file location:
mig2.exe - C:; C:\Windows or C:\Winnt
empty.pif - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
iexplorer.exe, shell.exe, mrhelloween.scr - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
csrss.exe, lsass.exe, services.exe, smss.exe, winlogon.exe - C:\Documents and Settings\[Current User]\Local Settings\Application Data\Windows

Other programs to remove Hiween:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 08/09/06
Information updated: 08/09/06

Additional resources related to Hiween:

Attention: If you know or you have a website or page about Hiween removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Hiween parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: