Rahiwi.b manual removal:
Kill processes:
shell.exe, winme.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\winme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%Windir%\winme.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsfot\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe %Windir%\winme.exe
HKEY_CLASSES_ROOT\batfile\Shell\Open\Command\(Default)=%Windir%\Web\shell.exe "%1" %*
HKEY_CLASSES_ROOT\piffile\Shell\Open\Command\(Default)=%Windir%\Web\shell.exe "%1" %*
HKEY_CLASSES_ROOT\exefile\Shell\Open\Command\(Default)=%Windir%\Web\shell.exe "%1" %*
HKEY_CLASSES_ROOT\lnkfile\Shell\Open\Command\(Default)=%Windir%\Web\shell.exe "%1" %*
HKEY_CLASSES_ROOT\comfile\Shell\Open\Command\(Default)=%Windir%\Web\shell.exe "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger=%Windir%\Web\shell.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=%Windir%\winme.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\SystemRestore\DisableConfig=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\SystemRestore\DisableSR=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\DisableMSI=1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer\LimitSystemRestoreCHeckpointing=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
Delete files:shell.exe, winme.exe, empty.pif
Misc:Exact file location:
shell.exe - C:\WINDOWS\Web or C:\WINNT\Web
empty.pif - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
winme.exe - C:\WINDOWS or C:\WINNT; removable media, shared and local drives
Post Comment: