I didn't write the virus, so I have no clue, other than it shouldn't be there. If I were to write a virus I'd hide it somewhere where no one would expect, name it the same as legit windows filenames, or overwrite the real windows file, BUT later version like W7 will stop you from doing that in most cases, soooo, that is why it might be where it is.
Be careful of some of those links on the search page I posted, some are there to SELL you some sort of program to get rid of it, and it might NOT even to it.
Still, I'd use MSCONFIG and look on the STARTUP tab for a program that is 'odd'. Many of these use a bunch of letters and numbers stuffed into a TEMP directory. Booting into SAFE MODE might also allow you to run without the virus and is a good test. Then start unchecking the 'odd' MSCONFIG programs you do not recognize, eventually with trial and error you'll discover the culprit if it gets started the 'normal' process way.
There are more complicated ways to find it too, like Process Explore and filtering... need some skill possibly to do that, virus checkers should get it and it is easier that way.