Rahiwi manual removal:
Kill processes:
cute.exe, data_rahasia administrator.exe, iexplorer.exe, imoet.exe, shell.exe, smss.exe, tiwi.exe, tiwi_cute.exe, winlogon.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\msmsgs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\tiwi
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LogonAdministrator
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System Monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell=explorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=%System%\userinit.exe,%System%\iexplorer.exe
HKEY_CLASSES_ROOT\batfile\Shell\Open\Command\(Default)=%System%\shell.exe "%1" %*â€
HKEY_CLASSES_ROOT\comfile\Shell\Open\Command\(Default)=%System%\shell.exe" "%1" %*â€
HKEY_CLASSES_ROOT\exefile\Shell\Open\Command\(Default)=%System%\shell.exe" "%1" %*â€
HKEY_CLASSES_ROOT\inffile\Shell\Install\Command\(Default)=%System%\shell.exe" "%1" %*â€
HKEY_CLASSES_ROOT\lnkfile\Shell\Open\Command\(Default)=%System%\shell.exe" "%1" %*â€
HKEY_CLASSES_ROOT\piffile\shell\Open\Command\(Default)=%System%\shell.exe" "%1" %*â€
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\AlternateShell=%Windir%\tiwi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger=%System%\shell.exe
HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE=%Windir%\system32tiwi.scr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption=[string1]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispSettingsPage=1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductID=[string2]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName=[string3]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization=[string4]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner=[string5]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeText=[string6]
Delete files:cute.exe, data_rahasia administrator.exe, iexplorer.exe, imoet.exe, shell.exe, smss.exe, tiwi.exe, tiwi_cute.exe, winlogon.exe, rpcss.dll, empty.pif, tiwi.scr
Delete directories:C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS
Misc:Exact file location:
tiwi.exe - C:\WINDOWS or C:\WINNT; C:
empty.pif - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
data_rahasia administrator.exe - available drives including removable media and shared disks
iexplorer.exe, shell.exe, rpcss.dll, tiwi.scr - C:\WINDOWS\System32 or C:\WINNT\System32
smss.exe, winlogon.exe - C:\Documents and Settings\Administrator\Local Settings\Application Data
cute.exe, tiwi_cute.exe, imoet.exe - C:\Documents and Settings\Administrator\Local Settings\Application Data\WINDOWS