Inker.B manual removal:
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iexploit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ipnuker
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page=%Windir%\iecrash.html
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page=%Windir%\iecrash.html
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Security Center\AntivirusDisableNotify=1
HKEY_CURRENT_USER\Software\Microsoft\Security Center\FirewallDisableNotify=1
HKEY_CURRENT_USER\Software\Microsoft\Security Center\UpdatesDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntivirusDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1=cmd.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\2=wuauclt.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3=sndrec32.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4=sndvol32.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\5=wmplayer.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\6=acrord32.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\7=mspaint.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\8=rstrui.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\9=aupdate.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=1
HKEY_CLASSES_ROOT\bmpfile\Shell\Open\command=%Windir%\ipnuker.vbs
HkEY_CLASSES_ROOT\Folder\Shell\Explore\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\Folder\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\exefile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\jpegfile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\jpgfile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\htmlfile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\HTTP\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\https\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\inffile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\inifile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\mpegfile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\mpgfile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\mp3file\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\txtfile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\wmafile\Shell\Open\command=%Windir%\ipnuker.vbs
HKEY_CLASSES_ROOT\batfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\bmpfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\comfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\exefile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\htmlfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\jpegfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\jpgfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\inffile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\inifile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\mpgfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\mp3file\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\vbsfile\DefaultIcon=shell32.dll,2
HKEY_CLASSES_ROOT\wmafile\DefaultIcon=shell32.dll,2
HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Norton Antivirus\Quarantine\QuarantinePath=windir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner=ipnuker
Delete files:createuser.vbs, ipnuker.vbs, hotmail password finder.vbs, script.ini, iecrash.html, iexploit.html