Hiween manual removal:
Kill processes:
csrss.exe, iexplorer.exe, lsass.exe, mig2.exe, services.exe, shell.exe, smss.exe, winlogon.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\logon [X]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mig2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msmsgs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services [X]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %System%\iexplorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%System%\iexplorer.exe
HKEY_CLASSES_ROOT\batfile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_CLASSES_ROOT\piffile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_CLASSES_ROOT\exefile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_CLASSES_ROOT\lnkfile\Shell\Open\Command\(Default)=%System%\shell.exe %1 %*
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=%Windir%\mig2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger=%System%\shell.exe
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe=%System%\mrhell~.scr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\SystemRestore\DisableConfig=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\DisableMSI=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\LimitSystemRestoreCheckpointing=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\FullPathAddress=1
Delete files:csrss.exe, iexplorer.exe, lsass.exe, mig2.exe, services.exe, shell.exe, smss.exe, winlogon.exe, mrhelloween.scr, empty.pif
Misc:[X] is the current user name.
Exact file location:
mig2.exe - C:; C:\Windows or C:\Winnt
empty.pif - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
iexplorer.exe, shell.exe, mrhelloween.scr - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
csrss.exe, lsass.exe, services.exe, smss.exe, winlogon.exe - C:\Documents and Settings\[Current User]\Local Settings\Application Data\Windows