Orkut is banned you fool !!! New Virus by Microsoft !!!

Friday, May 18, 2007

Orkut is banned you fool, The administrators didn't write this program guess who did?? MUHAHAHA!!

This has been one of the latest funny and cool virus around. I have seen it in two of my friends places already.

When you open Mozilla it says I DNT HATE MOZILLA BUT USE IE OR ELSE... with title as USE INTERNET EXPLORER U DOPE.

Here are the steps to remove it from your system.

  1. Open Task manager by pressing CTRL+ALT+DEL and go to the processes.
  2. Locate svchost.exe. There will be many but look for the ones which have your current username under the username.
  3. Right click and give end program and then terminate that process.
  4. Repeat for more svchost.exe files with your username and repeat. Do not kill svchost.exe with system, local service or network service!
  5. Now open My Computer
  6. In the address bar, type C:\heap41a and press enter. It is a hidden folder, and is not visible by default.
  7. Delete all the files here.
  8. Now go to Start --> Run and type Regedit
  9. Go to the menu Edit --> Find
  10. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
  11. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
  12. Now close the registry editor.
Now the virus is gone. But be sure to delete the autorun.inf file and any folder whose name ends with .exe in the pen drive.

courtesy : http://mgharish.blogspot.com/2007/05/i-dnt-hate-mozilla-orkut-is-banned.html
I got this on the above blog after googling.
Under
  1. Check out the two different solutions here
    http://meninweb.blogspot.com/2007/05/i-dnt-hate-mozilla-but-use-ie-or-else.html

  2. ashish

    Thanks alot buddy.

  3. Grapher

    think he left this solution

    III - Deleting the registry entries
    Go to Start>Run (or Windows key + R)
    Type in regedit and hit Enter
    Navigate to HKEY_LOCAL_MACHINE,SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run and delete the winlogon key. This will prevent any remnants of the worm from starting at booting.

    IV Editing the registry to restore the “View Hidden Files” option
    In Regedit, navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden
    There, navigate to NOHIDDEN
    In NOHIDDEN, change the CheckedValue to “0? and DefaultValue to “1?.
    Go one step back, and navigate to SHOWALL
    In SHOWALL, change the CheckedValue to “1?.

    Thats it

Post a Comment