-->

相爱容易相处难,相处容易相信难,相信容易相谅难。相信是最难的,但是包容对方又会更难。夫妻之道忠恕而已,忠于自己,忠于对方,宽恕对方,宽恕错误。
干干净净的离了,再干干净净的找。干净的爱情,每个人都有资格拥有,无论你的过去是什么样子。我想说:我们所要面对的事情,是现在和将来。过去,仅是历史,何必纠结。

Malware - "youtube IS BANNED"

Yesterday nite, when i think i will going watch youtube and go browser to open it. when all a sudden youtube opened up for a few seconds, and then close and a popup error message appeared.

(title of error message) youtube IS BANNED
"youtube is banned you fool,The administrators didnt write this program guess who did??"
"MUHAHAHA!!"

(The grammar mistakes are intentional.. this is a transcript)
And an audio clip of evil laughter (sorta like as in the message) plays.. now if I try typing youtube in the address bar, IE closes and that same message with the audio clip comes up! I've tried clearing my cache but that doesn't seem to work.

Ppl hv experince about this problem. So they also tried using Mozilla FireFox but it says,

(Error message title) USE INTERNET EXPLORER YOU DOPE"I DNT HATE MOZILLA BUT USE IE OR ELSE..."

And, the error message seems to automatically close after 5 seconds.

How to resolve this problem?Below the solution:-
Run a virus scan and delete any viruses/trojan
THEN, restart and open up in safe mode and scan again.
If worse comes to worse back up your files and re-format.
EDIT; I did some research - this might come in handy.

Here is how to remove the Malware:
When you get the Message:
1. Go to the Task Manager
2. Click on the "Application Tab."
3. Right click on the application that is giving the message and select "go to process."
4 "Svchost.exe" should be highlighted.
5. Right Click and Select "End Process Tree"

If you really wanna get rid of the Malware there is a File called "heap41a" which is located in "C:\heap41a."This is the script in the file"

#persistent
#notrayicon
settimer,ban,2000
return

ban:
WinGetActiveTitle, ed
ifinstring,ed,orkut
{
winclose %ed%
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ifinstring,ed,youtube
{
winclose %ed%
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ifinstring,ed,Mozilla Firefox
{
winclose %ed%
msgbox,262160,USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA
BUT USE IE `r OR ELSE...,30
return
}
ifwinactive ahk_class IEFrame
{

ControlGetText,ed,edit1,ahk_cl... IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit2,ahk_cl... IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit3,ahk_cl... IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit4,ahk_cl... IEFrame
ifinstring,ed,orkut
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,ORKUT IS BANNED,Orkut is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit1,ahk_cl... IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit2,ahk_cl... IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit3,ahk_cl... IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}
ControlGetText,ed,edit4,ahk_cl... IEFrame
ifinstring,ed,youtube
{
winclose ahk_class IEFrame
soundplay,C:\heap41a\2.mp3
msgbox,262160,youtube IS BANNED,youtube is banned you fool`,The
administrators didnt write this program guess who did??
`r`r MUHAHAHA!!,30
return
}

}

return


Two websites which are been blocked...(Orkut and youtube)

Delete "C:\heap41a"

2 Opinions:

Dragon Head said...

huah.. cool cool... by the way, u know where did u get this malware?? or where i can download it.. hehehe

leon said...

u hvnt see intruction in my post meh?....if u wan software to download, search urself...there hv many software can remove all malware.