Tuesday, June 05, 2007

Orkut and Youtube worm!!!!!

Viruses are getting better by the day... they not just wreak havoc with the comps ... now they even laugh at your face!!!! no im not kidding... THEY LAUGH MUHAHHAHAHAHAH AT YOUR FACE!!!!! what balls!!!!


This happened about a week ago. I had some taken a friend’s pen drive to transfer some music onto my computer. After a while, I casually decided to check my mailbox. I tried opening mozilla and the computer threw a very strange message.

“ I do not have anything against mozilla but use IE otherwise…”
I was quite shocked. “Bill Gates???”

I hate IE. So I did everything possible to get Mozilla running but it was just not possible. I reluctantly opened IE and tried logging onto Orkut.

“Orkut is banned. The administrators have not written this program. Guess who??” Like it was not frustrating enough, a loud gross voice laughs at ur face… I was losing it … seriously!!!

This happened with youtube as well…Just imagine… u have a laptop… a high speed internet connection… yet you cant use orkut or youtube… and you cant use the mozilla browser.

I tried uninstalling and reinstalling mozilla but it was not working. This went on for a week. Today I happened to find the manual "virus slaying" technique… am I excited or what!!!

Just in case you’ve also managed to get yourself into the shit-hole… here’s the remedy:

Log into windows in the safe mode (This you can do by repeatedly pressing F8 button after switching on the machine)

Search for svchost.exe in the system. Look for the files that do not lie in the windows folder and note down the path.The worm does not allow you to access hidden folders. So you have to first change the registry entries. Go to start à run and type regedit

Go to the following path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\currentversion
\Explorer\Advanced\Folder\Hidden\SHOWALL and change the key from 2 to 1.

This will enable you to see the hidden files in the system.

Now check the path of the svchost.exe file. You will find that there will be a svchost.exe in C:\heap41a folder. This folder is created by the virus and has the associated mp3 and the script files. Delete this folder manually either directly in windows or through DOS.

Now go to:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\currentversion
\Policies\Explorer\Run. The key there will contain a path to the worm folder. Clear this key.

This clears the system of the w32.USBWorm.

This worm spreads through the USB port… so to prevent this irritating virus from entering your computer, disable the auto-run facility on your windows and always scan the USB device with a trusted anti-virus.

Im just hoping they wont try to get back at me now!!!! Phew!!!!

2 comments:

Anonymous said...

Whoa !!! great going ellie :)

Anonymous said...

same thing happened to me !!
the laughter was really menacing ..
brr...
but googled and got off soln ! yayy :P

btw , how's life?
how's your plan ;) coming along ??
:D

-prat