At which point the only file that was detected was called WxBug.EXE.2. Run a full system scan.
3. If any files are detected as W32.HLLW.Gaobot.BC, click Delete.
3. Restarting the computer in Safe mode or ending the Trojan process
Windows 95/98/Me
Restart the computer in Safe mode. All the Windows 32-bit operating systems, except for Windows NT, can be restarted in Safe mode. For instructions, read the document, "How to start the computer in Safe Mode."
Windows NT/2000/XP
To end the Trojan process:
1. Press Ctrl+Alt+Delete once.
2. Click Task Manager.
3. Click the Processes tab.
4. Double-click the Image Name column header to alphabetically sort the processes.
5. Scroll through the list and look for Winupdates.exe.
6. If you find the file, click it, and then click End Process.
7. Exit the Task Manager.
C:\WINDOWS|system32\regetit.com
The NTVDM CPU encountered an illegal instruction.
CS:053d IP:ffe4 OP:feff Id 09e9 choose "close" to terminate the application.
Formatting is a serious consideration in the back of my mind right now. As long as I'm getting help in this thread, I have hope that I won't have to do that, though.mikescorpio81 said:God! That problem of yours sounds terrible! How did u get that 180 spyware onto your pc? Dosen't your Spybot detect & delete or quarantine it?
Sypware really gets to me. I ran a search through Ad aware on my wifes sisters pc last weekend & it found 185 infected files! Thats just from her general browsing & shes only had her laptop for 1 month! Stupid advertisment!
How about u save all of your stuff, format & start fresh?
Don't listen to me though ... im currently in training!!!
Quite simple Windows goes through the possible extensions alphabetically. .com comes before .exe. Therefore if you just type calc in the Run box Windows will run calc.exe unless of course someone stuck a prog named calc.com in which case this would be executed.rubjonny said:... For whatever reason regedit.com takes priority over regedit.exe and will run if you type 'regedit' in the run box. If you type 'regedit.exe' then you should get the registry editor.