Thursday, January 17, 2008

Orkut virus

Internet ExplorerUSE INTERNET EXPLORER U DOPE.
I DNT HATE MOZILLA BUT USE IE OR ELSE...
Other messagesWhen visiting Orkut.com :
"ORKUT IS BANNED. Orkut is banned you fool, The administrators didnt write this program guess who did?? MUHAHAHA!!"

When visiting YouTube.com: "youtube IS BANNED. youtube is banned you fool, The administrators didnt write this program guess who did?? MUHAHAHA!!"

"I DNT HATE MOZILLA BUT USE IE" OR ELSE... with title as USE INTERNET EXPLORER U DOPE.

When you opened Orkut. "Orkut is banned you fool, The administrators didn't write this program guess who did?? MUHAHAHA!! with title ORKUT IS BANNED." Well, a similar message was displayed for YouTube also.

How to fix your computerVirus backgroundIf any of the above conditions appear while you are using Firefox, you have been infected with the W32/AHKHeap virus.

This virus is spread via removable drives such as USB removable drives. For more information, see "W32/AHKHeap" virus. Removing the virusTo remove this virus, you can use online anti-virus tools.

The following scanners run in your browser using a plugin, and also can remove/repair many infections:* Trend Micro HouseCall - Java or ActiveX* Panda ActiveScan - ActiveX only (IE only)* eTrust Antivirus Scanner - ActiveX only (IE only) You also can use antivirus software you install on your computer. The following commercial products are popular with Windows users:* McAfee VirusScan Plus* Norton AntiVirus 2007

IF you face some errors in such way, read the rest..

1. Press CTRL+ALT+DEL and go to the processes tab
2. Look for svchost.exe under the image name.
There will be many but look for the ones which have your username under the username
3. Press DEL to kill these files. It will give you a warning, Press Yes
4. Repeat for more svchost.exe files with your username and repeat. Do not kill svchost.exe with system, local service or network service!
5. Now open My Computer
6. In the address bar, type C:\heap41a and press enter. It is a hidden folder, and is not visible by default.
7. Delete all the files here
8. Now go to Start --> Run and type Regedit
9. Go to the menu Edit --> Find
10. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
11. Select that and Press DEL. It will ask "Are you sure you want to delete this value?", click Yes
12. Now close the registry editor.

Now the virus is gone. But be sure to delete the autorun.inf file and any folder whose name ends with .exe in the pen drive.Note: Please format all your pen drives because the virus is in that hidden in an microsoft.exe autorun.inf which you might not find. Else you might have to repeat all this everytime! Further reading click here

No comments: