Got a flag this morning purporting to be from Vista saying my laptop was basically crawling with viruses, mal ware etc etc ... the extent of the 'infection' (and that it hadnt come from Norton!) tipped me off that all was not as it seemed.
Having trawled the web and found out that this is a known piece of malware (still no idea how I picked it up as I am dam careful of installs) I set about getting rid of it.
1) Firstly full NAV scan comes up negative apart from a usual tracking cookie or 2.
2) I looked at various sites who had manual instructions for removal but many of these want me to instal their anti-virus/spyware removal software which I am loath to do as (a) I have NAV and (b) I dont know these folks and could end up in a worse position!
3) I had a look at the manual removal instructions with the following result:
a) I did find an av.exe process running on my machine which I ended ... didn't find any otf the other named processes.
b) I cant find any of the .exe files under either "av.exe" or "av2010.exe" anywhere on my machine
There is a c:\users\andrew\appdata\local\temp\low\av.exe entry in the registry but cant navigate to the file
c) checking the registry I cant find the specific entries noted on the sites (although they do differ depending on the site checked) ... I have searched for av.exe and av2010.exe but only found the one I noted above
d) a run of Systemworks (basically to see if it flags issues, particularly registry ones) didnt flag up anything relevant.
Questions are (yes they were a long time coming):
1) Is my machine now clear?
2) should I delete the av.exe reg entry and or the file it points to? Not sure if the file actually exists as I cant navigate to it.
3) is a registry search for "av.exe" and "av2010.exe" enough to confirm that they are not there?
4) Why is this not picked up/cleaned by NAV? Not attaching blame but want to make sure I dont get this again :-)
Any help appreciated