[Solution] Orkut.com, Youtube.com and Firefox is Banned in System



Many people are facing a common problem, where Orkut.com, Youtube.com and Firefox are blocked in their systems and they get following error with a scary laugh:

Orkut IS BANNED, orkut is banned you fool The administrators didnt write this program guess who did?? r r MUHAHAHA!!

So here I'm posting a detailed procedure to solve this problem.

It happens bcoz of "Heap41a / win32.USBworm" which spreads through USB pen drives and removable storage devices. I'll tell you manual as well as automatic method to remove the virus:

-------------------------

A. MANUAL METHOD:

Follow these instructions:

1. Open "Task Manager" and goto "Processes" tab.

2. Look for services with name "svchost.exe". There will be many services with the same name. Most of them will have "SYSTEM", "LOCAL SERVICE" OR "NETWORK SERVICE" as User Name but you have to look for "svchost.exe" service which has your currently logged in username as User Name.

3. You'll get approx. 2 services with the name "svchost.exe" which has your Windows username. End Task them by pressing <Delete> key or by selecting them and clicking on "End Process" button. It'll confirm the action, accept it.

4. Now open "regedit" from RUN and goto following keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Policies\Explorer\Run

And look for a key in right-side pane with the name "Winlogon" which will have "heap41a\svchost.exe" in its value field. If you find this key, delete it.

5. Now goto following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\explorer\Advanced\Folder\Hidden\SHOWALL

And in right-side pane, change value of "CheckedValue" to 1

6. Now enable "Show Hidden Files/Folders" option in "Tools -> Folder Options" in My Computer.

7. Right-click on Start button and select "Open". Now open "Programs" folder, here you'll see a folder "Startup". Open it and if you get a hidden file there, delete it. If its not there, then close it.

8. At last open "My Computer" and open C: drive. Disable "Hide Protected System files" option in "Tools -> Folder Options". You'll see a folder "heap41a" in C: drive. Delete it.

Thats it. After doing all this, restart your system and you'll get rid of the virus.

-------------------------

B. AUTOMATIC METHOD:

Just download following tool and run it:

Download Orkut blocking Worm Removal tool

-------------------------

Don't forget to format your pen drive or removable storage media which caused this virus infection coz it would still contain the virus. If you don't want to format it, then delete following 2 files from pen drive:

microsoftpowerpoint.exe
autorun.inf

Complete list of AskVG articles



This article was posted in Mozilla Firefox, Others, Troubleshooting.


Share |


Related Articles

Popular Articles



73 Comments

  • can u tell what r these proxy sites..................

  • VG

    ^^ Proxy sites help in opening sites which have been blocked by administrator. Not always but sometimes.

  • That was so relieving... thanks man...100% voted....

  • VG

    Welcome. :)

  • :smile: thanks for help

  • thanks for giving the solution from this virus.

  • really its very nice...........

  • You are indeed a genius........... :smile:

    Thanks for helping us.............

  • Hi All,
    My system is infected by a nasty virus and when ever I login to orkut it automatically sends a file to all those in my friends list. Recently it sent some adult content causing embarrassment to all. Request you to pls help me get rid of that dirty virus.
    Regards,
    Sandeep

  • VG

    ^^ I have mentioned which entries you should fix in HijackThis in the other topic, so please fix them in Safe mode.

Add a Comment

NOTE: If you can't see your comment, please be patient. It'll appear as soon as we approve it.


Create an avatar that will appear with your comment.