resides in c:\$Windows$ \orawin.exe <-- virus/worm. c:\$Startup$\orawin.exe in registry run (startup applications) 'HP_spooler' Sad to say NOD32 didn't detect it at all. Even when i had it scanned specifically for that file only. Virus restarts your system when you hit CTRL+ALT+DEL when you try to terminate it, im not sure what damage it would do. File looks like an ordinary notepad which you would have thought a text file but instead it's an application. Author says '++'. Luckily you can remove it from safe mode and with the help of some info on the web. Didn't have much time to print screens and save a copy of the virus. Got dismayed and feel bad for NOD32 didn't catching this one.