Mozzila banning virus “ORKUT IS BANNED” ” I DNT HATE MOZILLA BUT USE IE OR ELSE…USE INTERNET EXPLORER U DOPE” “youtube IS BANNED”

Some net geek has written a script to block you from accessing orkut, youtube from any browser and disable your access from using Mozilla Firefox web browser. After long time of analysis and search i figured out the way to remove this virus from your PC.

Affected OS: Windows XP/Vista

Symptom: A pop up with message like I DNT HATE MOZILLA BUT USE IE OR ELSE…” “USE INTERNET EXPLORER U DOPE” whenever you try to open your Mozilla web browser

“Orkut is banned you fool” whenever you try to open orkut even from your IE. similarly “youtube IS BANNED”

Source file: source file is the windows script, and this file can be identified from c:\heap41a or c:\heap64 folder, these files are in hidden stage

PROCESS TO REMOVE:

To remove this virus do the following in sequence…

i. go to c:\\ and use user Tools -> folder options and show all hidden files.

ii. If the file is visible get in to the folder and try to delete it. Normally this script is been set to start automatically as part of your system startup process. So when it is active you cann’t delete it. use ctrl + alt+delte, and go to the process.

iii. In this virus affected PCs there will be plenty of svhost.exe running. Normaly it is used for you network and host related operation. Try to stop any of the available process. If your lucky enough you will be able to disable the right process, and you can delete the script from heap41a or hea64 folder. IF not a automatic pupup alter will come this will restart your PC within 60 secs. be fast stop remaining svhost.exe and try to delete the file.

If you are not able to stop wrong svhost.exe no problem follow the next step disable the srevice in the startup script and than delete it.

iv. If you delete the right process without getting an alert follow this step, or after deleting the file try this process. in start -> run type msconfig and go to start up. un-check the link which calls the process c:\\heap41a\svhost.exe or c:\\heap64\svhost.exe

If you succeed till this step do one more reboot you are free from the virus. If not try to do it again and again.

In special cases if you are not able to view the hidden files even after enabling the show hidden option, use ms-dos prompt and delete the script.

IF not follow the steps to view the hidden file using regedit options.

Go to registry editor by running regedit in the run box.
Go to this key:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\Advanced

In the right hand area, double click hidden and change the value to 1.

Now you’re all set to go.

USE “SHIFT + DELETE ” friends, Check and SCAN your pen drives any other floppy or CDs thoroughly before copying or sharing any files between PCs this will prevent the spreading of these viruses.

Hope this helps you to escape from those net geek assholes.

******* Common guys get ready to slaughter these net cracks*******

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • FriendFeed
  • MySpace
  • Reddit
  • StumbleUpon
  • Technorati
  • Twitter
  • Yahoo! Bookmarks
  • Yahoo! Buzz

Post to Twitter Tweet This Post

POSTED BY simba on Dec 14 under MY Scribbles

Leave a Comment

If you would like to make a comment, please fill out the form below.

Name (required)

Email (required)

Website

Comments

Copyright Simba's Soccer Scribbles and more | Powered by WordPress | Using the GreenTech Theme

Twitter links powered by Tweet This v1.6.1, a WordPress plugin for Twitter.