<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: w32.USBWorm lets remove this worm manually</title>
	<atom:link href="http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/</link>
	<description>Let's talk life!</description>
	<lastBuildDate>Sat, 23 Jan 2010 20:22:36 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jeba&#8217;s Blog &#187; Blog Archive &#187; 5 Tips to fight Pen/USB Drive Viruses</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-121801</link>
		<dc:creator>Jeba&#8217;s Blog &#187; Blog Archive &#187; 5 Tips to fight Pen/USB Drive Viruses</dc:creator>
		<pubDate>Mon, 13 Apr 2009 12:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-121801</guid>
		<description>[...] we share data. Every now and then one of your friend pops into your house with his pen drive and inserts it into your System to copy what ever he wants and ends up infecting your system with some virus without his/her [...]</description>
		<content:encoded><![CDATA[<p>[...] we share data. Every now and then one of your friend pops into your house with his pen drive and inserts it into your System to copy what ever he wants and ends up infecting your system with some virus without his/her [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashoka BL</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-108939</link>
		<dc:creator>Ashoka BL</dc:creator>
		<pubDate>Sun, 14 Dec 2008 05:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-108939</guid>
		<description>Hi Guyz,

its really awesome worm...took almost 2 hours for me to figure out, somehow using advanced search i got the location of microsoftpowerpoint.exe i deleted the folder but still i was getting the same error. I was able to see all the hidden folders but not the heap41a,i was going mad...and then thought lemme try with command prompt, and banggg....i found the folder in c:\, i deleted all the files and then deleted the folder and here i am happily got into orkut.


one suggestion, when u guyz use the thumb drive dont have an autorun option.

Thanks pals, and thanks Jeba u rock.


Regards,
Ashoka BL
Bangalore</description>
		<content:encoded><![CDATA[<p>Hi Guyz,</p>
<p>its really awesome worm&#8230;took almost 2 hours for me to figure out, somehow using advanced search i got the location of microsoftpowerpoint.exe i deleted the folder but still i was getting the same error. I was able to see all the hidden folders but not the heap41a,i was going mad&#8230;and then thought lemme try with command prompt, and banggg&#8230;.i found the folder in c:\, i deleted all the files and then deleted the folder and here i am happily got into orkut.</p>
<p>one suggestion, when u guyz use the thumb drive dont have an autorun option.</p>
<p>Thanks pals, and thanks Jeba u rock.</p>
<p>Regards,<br />
Ashoka BL<br />
Bangalore</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pranesh</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-91761</link>
		<dc:creator>Pranesh</dc:creator>
		<pubDate>Thu, 31 Jul 2008 05:58:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-91761</guid>
		<description>Thks a lot ...
U ll be remembered by many for ur help !!!</description>
		<content:encoded><![CDATA[<p>Thks a lot &#8230;<br />
U ll be remembered by many for ur help !!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eldhose</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-91316</link>
		<dc:creator>eldhose</dc:creator>
		<pubDate>Mon, 28 Jul 2008 04:27:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-91316</guid>
		<description>thank u ... man</description>
		<content:encoded><![CDATA[<p>thank u &#8230; man</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bhise</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-90128</link>
		<dc:creator>bhise</dc:creator>
		<pubDate>Sun, 20 Jul 2008 17:11:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-90128</guid>
		<description>Can any halp in removing this virus

Surabaya in my birthday
Don&#039;t kill me, i&#039;m just send message from your computer
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti
Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan dalam sesal
Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0</description>
		<content:encoded><![CDATA[<p>Can any halp in removing this virus</p>
<p>Surabaya in my birthday<br />
Don&#8217;t kill me, i&#8217;m just send message from your computer<br />
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti<br />
Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku<br />
Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan dalam sesal<br />
Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arushi</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-88660</link>
		<dc:creator>arushi</dc:creator>
		<pubDate>Wed, 09 Jul 2008 11:42:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-88660</guid>
		<description>thanx a tonnn 4 such a detailed xplanation.....i ws searching 4 1 y dis</description>
		<content:encoded><![CDATA[<p>thanx a tonnn 4 such a detailed xplanation&#8230;..i ws searching 4 1 y dis</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ADS</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-88443</link>
		<dc:creator>ADS</dc:creator>
		<pubDate>Mon, 07 Jul 2008 17:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-88443</guid>
		<description>Can u please throw some info on the below mentioned virus. My Kaspersky says deleted. Will I have to do anything more?

Virus.Win32.Hidrag.a</description>
		<content:encoded><![CDATA[<p>Can u please throw some info on the below mentioned virus. My Kaspersky says deleted. Will I have to do anything more?</p>
<p>Virus.Win32.Hidrag.a</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Onesimus</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-87836</link>
		<dc:creator>Onesimus</dc:creator>
		<pubDate>Fri, 04 Jul 2008 07:59:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-87836</guid>
		<description>Hi Jeba,
Greetings mate. Nice blog. I have seen many people face this problem with this worm with all those annoying messages :-). Thanks for the info you have given. I am goin to try this now. Thanks a lot anyways. God bless you abundantly. Take care.</description>
		<content:encoded><![CDATA[<p>Hi Jeba,<br />
Greetings mate. Nice blog. I have seen many people face this problem with this worm with all those annoying messages <img src='http://www.jeba.in/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . Thanks for the info you have given. I am goin to try this now. Thanks a lot anyways. God bless you abundantly. Take care.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alpesh</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-87690</link>
		<dc:creator>Alpesh</dc:creator>
		<pubDate>Thu, 03 Jul 2008 12:01:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-87690</guid>
		<description>Orkut is banned, dont try to open it, since it is restricted!!!
Posted on May 5, 2008 12:45:47 PM &#124; Filed under: Uncategorized 




Yesterday one of my friends called me up and told me that he cannot open any of the files in his Pen drive and was getting a message something related to ’system.exe’, 

Firstly I thought there could be some bad sectors in his drive so I told him to bring his drive to my home so that I could check it out.

When I inserted the drive into my laptop, the message popped up in my system also, I cant recall the message but I can tell u that it was for the file ’system.exe’ and below it there were two buttons ‘yes’ and ‘no’, accidently I clicked the yes button and then my system restarted.

On the restart I came to know that my antivirus was disabled, then I tried to open the task manager but it also appeared for only 2-3 seconds. Then I came to know that my system is affected with a virus and my first guess was W32.USBWorm. 

Ok I wont go into the details now and will tell u the virus symptoms and how to remove it.

Symptoms: 

1)      The Task manager shows up for 2-3 sec and then the message comes “—SORRY—       –SAM–”.

2)      When u try to access orkut then the message “Orkut is banned, don’t try to open it since it is restricted!!!” is displayed.

3)      You cannot search anything related to the virus as the message “Obscene sites banned” or something like that is displayed.

4)      You cannot unzip or extract any zipped files.

5)      Most important one is that it also disables any antivirus.

6)      You wont be able to open 80% of your software, there would be some or the other error.

Actually I could find out only these symptoms, there could be more of them.

 

Removal Instructions:

1)      Restart the computer in Safe Mode by pressing F8 key during the restart and then selecting Safe  Mode from the list.

2)      Open the drive in which Windows is installed, in most cases it is “C:”.

3)      Go to Tools &gt; Folder Options &gt; View, search for the Radio button “Show hidden Files and Folders”, check it. Just below it there is a check box “Hide Protected Operating System Files”, uncheck it.

4)      Now in the ‘C:’ drive you will see a folder named “Config”, simply delete that folder.

5)      Now Open the registry editor by typing ‘regedit’ in the run dialog box.

6)      Go to the following Key :

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run], delete the key whose path is something like this “C:\config\system.exe”

And another edit, just do the above action with the below mentioned key also

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies]

7)      Restart the computer and you are done.</description>
		<content:encoded><![CDATA[<p>Orkut is banned, dont try to open it, since it is restricted!!!<br />
Posted on May 5, 2008 12:45:47 PM | Filed under: Uncategorized </p>
<p>Yesterday one of my friends called me up and told me that he cannot open any of the files in his Pen drive and was getting a message something related to ’system.exe’, </p>
<p>Firstly I thought there could be some bad sectors in his drive so I told him to bring his drive to my home so that I could check it out.</p>
<p>When I inserted the drive into my laptop, the message popped up in my system also, I cant recall the message but I can tell u that it was for the file ’system.exe’ and below it there were two buttons ‘yes’ and ‘no’, accidently I clicked the yes button and then my system restarted.</p>
<p>On the restart I came to know that my antivirus was disabled, then I tried to open the task manager but it also appeared for only 2-3 seconds. Then I came to know that my system is affected with a virus and my first guess was W32.USBWorm. </p>
<p>Ok I wont go into the details now and will tell u the virus symptoms and how to remove it.</p>
<p>Symptoms: </p>
<p>1)      The Task manager shows up for 2-3 sec and then the message comes “—SORRY—       –SAM–”.</p>
<p>2)      When u try to access orkut then the message “Orkut is banned, don’t try to open it since it is restricted!!!” is displayed.</p>
<p>3)      You cannot search anything related to the virus as the message “Obscene sites banned” or something like that is displayed.</p>
<p>4)      You cannot unzip or extract any zipped files.</p>
<p>5)      Most important one is that it also disables any antivirus.</p>
<p>6)      You wont be able to open 80% of your software, there would be some or the other error.</p>
<p>Actually I could find out only these symptoms, there could be more of them.</p>
<p>Removal Instructions:</p>
<p>1)      Restart the computer in Safe Mode by pressing F8 key during the restart and then selecting Safe  Mode from the list.</p>
<p>2)      Open the drive in which Windows is installed, in most cases it is “C:”.</p>
<p>3)      Go to Tools &gt; Folder Options &gt; View, search for the Radio button “Show hidden Files and Folders”, check it. Just below it there is a check box “Hide Protected Operating System Files”, uncheck it.</p>
<p>4)      Now in the ‘C:’ drive you will see a folder named “Config”, simply delete that folder.</p>
<p>5)      Now Open the registry editor by typing ‘regedit’ in the run dialog box.</p>
<p>6)      Go to the following Key :</p>
<p>[HKCU\Software\Microsoft\Windows\CurrentVersion\Run], delete the key whose path is something like this “C:\config\system.exe”</p>
<p>And another edit, just do the above action with the below mentioned key also</p>
<p>[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies]</p>
<p>7)      Restart the computer and you are done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: priyanka</title>
		<link>http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/comment-page-3/#comment-87009</link>
		<dc:creator>priyanka</dc:creator>
		<pubDate>Sun, 29 Jun 2008 14:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeba.in/posts/w32usbworm-lets-remove-this-worm-manually/#comment-87009</guid>
		<description>thank you so much jeba...i was really frustrated with that worm....i am so very grateful to you..

bless you</description>
		<content:encoded><![CDATA[<p>thank you so much jeba&#8230;i was really frustrated with that worm&#8230;.i am so very grateful to you..</p>
<p>bless you</p>
]]></content:encoded>
	</item>
</channel>
</rss>
