December 10, 2007

“Orkut is banned” virus

Today my fren faced a very starange problem... while opening orkut in ie.. a starnge error came... smthing like this... “Orkut is banned you fool, The administrators didnt write this program guess who did?? MUHAHAHA!!” and the browser closed.
n finally i got d soln. from a fren's blog... so here it is:--

its actually W32.USBWorm virus which displayed such messages while opening Orkut and Youtube. Here are a few simple steps which you can follow to remove this virus if this has infected your system too.
    • Open the Task Manager by pressing Ctrl + Alt + Del and go to processes tab
    • Locate svchost.exe under the image name. There will be many processes by that name but look for the ones which have your username under the username. Just kill these processes by pressing Del key.Only kill those which have your username under the username and leave the rest
    • Open the run command and type C:\heap41a and press enter. This is a hidden folder. Delete all the contents of this folder
    • Open the registry by typing regedit in the run box
    • Search for heap41a in the registry by using the find command
    • You will get something like this “[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt“. Just delete the entries by pressing the del key
    • Close the registry editor

Now the virus will be gone. The virus mainly spreads through USB disks so be sure to delete Autorun.inf file and any folder which has a .exe extension in the pen drive you use. Avast and Nod32 are able to detect it. Even AVG, Norton and macfee failed to detect it.

No comments: