Although it is not a Windows core file it gets stored in the C:Windows or C:windowssystem32 folders and if deleted, it keeps coming back. This virus can also monitor applications and manipulate other programs.
Remove the Virus Completely in 3 simple steps:
1. Temporarily turn-off system restore on all drives. This is done because the system restore may back up the virus, worm, or Trojan on your PC and because windows is configured by default in such a way that outside programs, including antivirus software cannot delete or modify system restore, the infected files although found in system restore cannot be cleaned.
If it prompts you with a confirmation message click YES.
2. Update your antivirus program with the latest definitions and run a full system scan. If any suspicious files are detected try repairing them and in case they cannot be repaired just delete them.
3. Go to Start–> Run… and type regedit which opens registry editor window.
Note: Sometimes this threat can also prevent you from accessing system registry. If that’s the case with you, download this tool (UnHookExec) –> right click on it and choose install and restart your PC.
Now from the left pane of the registry editor window navigate to the subkey
In the right pane, delete the value: “auto” = “1”
Exit the registry and restart your computer.
Now you can turn-on system restore on all drives again.