Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Friday, November 16, 2007

Tutorial : To Remove Orkut Virus

Many users are facing a common problem, where Orkut.com, Youtube.com and Firefox are blocked in their systems and they get following error with a scary laugh:

Orkut IS BANNED, orkut is banned you fool The administrators didnt write this program guess who did?? r r MUHAHAHA!!

It happens because of "Heap41a / win32.USBworm" which spreads through USB pen drives and removable storage devices. There is a manual as well as an automatic method to remove the virus:

A. MANUAL METHOD:

Follow these instructions:

1. Open "Task Manager" and goto "Processes" tab.

2. Look for services with name "svchost.exe". There will be many services with the same name. Most of them will have "SYSTEM", "LOCAL SERVICE" OR "NETWORK SERVICE" as User Name but you have to look for "svchost.exe" service which has your currently logged in username as User Name.

3. You'll get approx. 2 services with the name "svchost.exe" which has your Windows username. End Task them by pressing key or by selecting them and clicking on "End Process" button. It'll confirm the action, accept it.

4. Now open "regedit" from RUN and goto following keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies
\Explorer\Run



And look for a key in right-side pane with the name "Winlogon" which will have "heap41a\svchost.exe" in its value field. If you find this key, delete it.

5. Now goto following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer
\Advanced\Folder\Hidden\SHOWALL


And in right-side pane, change value of "CheckedValue" to 1

6. Now enable "Show Hidden Files/Folders" option in "Tools -> Folder Options" in My Computer.

7. Right-click on Start button and select "Open". Now open "Programs" folder, here you'll see a folder "Startup". Open it and if you get a hidden file there, delete it. If its not there, then close it.

8. At last open "My Computer" and open C: drive. Disable "Hide Protected System files" option in "Tools -> Folder Options". You'll see a folder "heap41a" in C: drive. Delete it.

Thats it. After doing all this, restart your system and you'll get rid of the virus.

B. AUTOMATIC METHOD:

Just download following tool and run it:


Download Orkut blocking Worm Removal tool

Don't forget to format your pen drive or removable storage media which caused this virus infection because it would still contain the virus. If you don't want to format it, then delete following 2 files from pen drive:

microsoftpowerpoint.exe
autorun.inf

Original Source


I thank the original Author for writing such a nice tutorial.

Read the rest...

Digg Technorati del.icio.us Stumbleupon Reddit Blinklist Furl Spurl Yahoo Simpy

Friday, November 2, 2007

Warning : Deadly Computer Worm On The Prowl In India


A potentially dangerous computer worm called Storm has been silently infecting computers in India, creating a pathway into the system which can be exploited, either to steal data or flood your e-mail account with spams.

Having enticing subjects lines, the spam mails containing the worm baits people into opening them. Those who open the attachment then unknowingly become part of a Botnet (a collection of compromised computers running programmes having worms under a common command for nefarious purposes).

Experts in India said that the virus till now, has been infecting computers without causing serious damage. However, because it's gathering strength, experts are considering it a serious threat.

An expert said Storm travelled through spam and was showing no signs of slowing down. "It hasn't attacked till now. Yet, it is a disturbing trend. It continues to propagate and therefore grow in strength. This poses a serious threat because it may be preparing for a big attack during the festive season. Hackers could wreak serious damage if they unleash a denial-of-service attack with it. What's worse, you can't counter the attack by simply blocking a single server because its origin is distributed globally," the expert said.

A techie told TOI, "What makes Storm dangerous is that the content of the message keeps changing. It always has subject lines related to a contemporary occurrence somewhere in the globe."

Some of the subject lines have been "US secretary of state Condoleezza Rice has kicked German chancellor Angela Merkel", "a killer at 11, he's free at 21 and kills again", "British Muslims genocide", "log-in verification", "registration confirmation" and "happy labour day". The worm first appeared in January 2007 hiding in e-mail attachments with the subject line "230 dead as storm batters Europe".

For complete story follow this link

Read the rest...

Digg Technorati del.icio.us Stumbleupon Reddit Blinklist Furl Spurl Yahoo Simpy