Sounds like the Orkut Virus.WARNING:
The following involves a registry edit.
Improper changes to the registry could render your computer inoperable.
Remember to backup the registry, before
making any changes.
Instructions, on how to do that, can be found here:How to back up, edit, and restore the registry(I highly suggest, you make a copy of this article.)
Please follow all directions EXACTLY
, and in the same sequence.1.
Press CTRL+ALT+DEL and go to the Processes
Look for svchost.exe
under the Image Name
There will be many, but look for the ones which have your username, under the User Name
Click the entry, to highlight it, then click the End Process
It will give you a warning, click Yes
Repeat for all of the svchost.exe
files with your username.Do not kill svchost.exe with system, local service, or network service, under the User Name column!5.
Exit the Task Manager.6.
Open My Computer
In the address bar, type in; C:\heap41a
, and hit the Enter
Delete all the files found here.9.
Now, click Start
/ type in; regedit10.
Go to the toolbar, click Edit
, and select Find...11.
Type in; heap41a
, and click the Find Next
You will get something like this, [winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt13.
Right-click it, and select Delete
It will ask, "Are you sure you want to delete this value", click Yes
Exit the Registry Editor.
The Virus should now be gone.Note:
Please format all of your pen drives, because that's probably where you contracted the virus from, hidden in a microsoft.exe autorun.inf, which you might not find..
Edited by tg1911, 25 September 2007 - 11:57 PM.