How do I do that? It's very persistent.
Doesn't your AV software report the name and location of the virus' host?
Does it disable and/or quarantine the host code/program?
Does it have a feature or a log file that allows you to pinpoint the host code/program?
Can you send the warning message to the AV provider for confirmation that the offender is indeed malicious code?
Paj
8^?