If you're happy so are we. I meant this thing wasn't running from a reg key.
Maybe we are seeing a new generation of autoruuns, this one was reported in march 08. No autorun.inf reported with it.
We have one more file to look for.
Open HJT, run a system scan only, check mark these lines if present
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe Close all other browsers/windows, click fix, close HJT.
Use OTMOVEIT2 like you did before, with the drives plugged in
C:\amvo.* /s
D:\amvo.* /s
E:\amvo.* /s
F:\amvo.* /s
G:\amvo.* /s
H:\amvo.* /s
C:\amvo*.* /s
D:\amvo*.* /s
E:\amvo*.* /s
F:\amvo*.* /s
G:\amvo*.* /s
H:\amvo*.* /sA fter OTMOVEIT2 is finished, run Flash Drive Disinfecter, with the drives still plugged in. This will help prevent autorun infections.
You should now be able to clean up the tools you use.
* Click start button, run, then copy and paste the following line into the box and click ok.
Combo-Fix /u*Open OTMOVEIT2 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.
* Create a new restore point
You must be logged on to an administrator account
Go to Start - All Programs - Accessories - System Tools - System Restore.
Click Create a restore point, and then click Next.
In the text box labeled Restore Point Description, type a name for this restore point , click create
* Remove old restore points
- Go to Start - All Programs - Accessories - system tools. Launch the Disk Cleanup tool and let it run. When it finishes a box with tabs will appear, select the more options tab. On this tab you will find a section for System Restore. If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.
* Download and run this clean up utility. You can use it regularly. When it's first run, it is in demo mode to show you what it will remove. Review it and then rerun in real mode. It is configurable.
CleanUp by Steven Gould
http://www.stevengould.org/downloads/cleanup/* If you are using windows firewall, please note that it doesn't provide outbound protection. A third party firewall will.
A discussion on free firewalls can be found here.
http://forum.avast.com/index.php?topic=30808.0or
http://forum.avast.com/index.php?topic=33530.0* Check if you have insecure applications with
Secunia Software InspectorLet me know how you make out and if you still have problems. Plug your phone in and run flashdrive disinfecter on it too.