I haven't had the pleasure to meet & greet this fella on any of my own, but I just got drafted into fixing a computer (family!) that has this sneaky rat on it.
Obviously a google search is man's best friend when counter-attacking a virus (why re-invent the wheel?), so 4 pages look like they're dealing with this in a similar manner (link 1, link 2, link 3, and link 4).
So I took the long manual road to combat this.
1. First I rebooted the computer in "Safe Mode with networking" (not that I needed the network anyways). Oh, it's running Vista Home 32bit with 2gb RAM, /me sighs.
2 .Secondly, I search for all suggested keywords through the registry, and deleted the matched results.
3. Thirdly, deleted any physical files that came up as well (one was in C:\ProgramData\defender.exe, and the other was in C:\Windows\system32\{random characters}.exe).
4. Made sure no links/shortcuts existed, removed any suspicious entries in the Run/RunOnce registry keys, removed anything suspicious in the msconfig Startup.
5. Her computer was a legal registered (and current) copy of ESET nod32 antivirus on it, not even sure WHY this virus can bypass this, but it has, and continues to do so. Perhaps, it's more of a malware issue and not a virus? Anywoot, I run the ESET ecls.exe command line scanner before rebooting.
6. Her computer reboots, and appears to be FIXED! woot! Celebratory dinner follows! Drop her off after dinner, say my goodbyes and drive an hour to get home...
7. She calls me up later in the evening crying IT'S BACK like a damn minecraft creeper!

So, I quit, I throw in the towel, eff all this crap - it's all retarded anyways. I just tell her next time we meet, I'll backup your Documents folder, reformat, boost you up to 4 gigs of RAM, and install Windows 7 Professional 64bit and call it a day.
What would you have done differently?
