Originally posted by Kawazoe:
Yeah... it does RESTORE itself.
So far, Stinger worked quite well, except that it may crash.
http://tinybox.bravehost.com/OffAutoplay.htmlTurn off auto play in Windows first.
Then run a scan with Trend Micro to remove any viruses found.
[*]Please download Sysclean Package by Trend Micro and save it to your desktop.
[*]Download Virus Pattern Files by Trend Micro and save it to your destkop.
[*]Create a new folder on your desktop.
[*]Right click on your desktop.
[*]Click on New > Folder.
[*]Type in Trend Micro as the name of the folder.
[*]Select sysclean.com by clicking once. Press Ctrl + X simultaneously.
[*]Open the Trend Micro folder you created earlier. Press Ctrl + V to paste sysclean.com into the folder.
[*]Right click and select Extract All.
[*]Click on Browse. Navigate to the Trend Micro folder and click OK.
[*]Click Next, then Finish.
[*]Disconnect from the Internet and disable your antivirus temporary by right clicking on your antivirus and selecting Quit AVG Control Center.
[*]Close all opened windows except the Trend Micro folder.
[*]Double click on sysclean.com to run it.
[*]Check (tick) Automatically Clean Infected Files box.
[*]Once the scanning is done, click Exit.
[*]A sysclean.log is created in the Trend Micro folder.
[*]Copy and paste that log in your next reply.
[*]Re-enable your antivirus by going to Start > All Programs and open the antivirus again and connect back to the Internet.
Open Registry Editor (Start > Run, regedit)
Navigate to this key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
You should see "RavAV" = "%Windir%\RAVMON.EXE"
Delete this "RavAV" = "%Windir%\RAVMON.EXE".