<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JohnDas FunDas &#38; Ideas &#187; heap41a</title>
	<atom:link href="http://www.fundazone.com/ideas/heap41a/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fundazone.com</link>
	<description>Ideas, fundas, tips &#38; tricks - common and uncommon sense &#38; stuff u want on the internet</description>
	<lastBuildDate>Mon, 15 Feb 2010 13:52:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Show hidden files and folders not working &#8211; after virus attack (heap41a svchost.exe)</title>
		<link>http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/</link>
		<comments>http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/#comments</comments>
		<pubDate>Thu, 13 Sep 2007 08:18:33 +0000</pubDate>
		<dc:creator>FunDa</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[celebrity]]></category>
		<category><![CDATA[disasters]]></category>
		<category><![CDATA[discovery]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[heap41a]]></category>
		<category><![CDATA[missions]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[problems]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[tricks]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[websites]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/</guid>
		<description><![CDATA[I had this problem.
The best way to remove a computer virus is like a doctor treats viral infections.
A doctor’s approach to a USB drive viral infection
In Tools&#62; Folder options &#62; View &#8211; hidden files and folders
The
Show hidden files and folders not working &#8211; after virus attack (heap41a svchost.exe)
This is how you get the settings back [...]]]></description>
			<content:encoded><![CDATA[<p>I had this problem.</p>
<p>The best way to remove a computer virus is like a doctor treats viral infections.</p>
<h2 class="post-title"><a title="Permanent Link: A doctor’s approach to a USB drive viral infection" rel="bookmark" href="../2007/06/a-doctors-approach-to-a-usb-drive-viral-infection/">A doctor’s approach to a USB drive viral infection</a></h2>
<p>In Tools&gt; Folder options &gt; View &#8211; hidden files and folders</p>
<p>The</p>
<p><strong>Show hidden files and folders</strong> not working &#8211; after virus attack (heap41a svchost.exe)</p>
<p>This is how you get the settings back to normal.</p>
<p>First take</p>
<p><strong>Start &gt; Run &gt;</strong></p>
<p>Type <strong>regedit</strong> in the Run box and click <strong>OK</strong></p>
<p>The Registry editor opens up (See the image below)</p>
<p>Follow the steps in the animation below to get back the folder options to normal to see hidden files.</p>
<p><img src="http://www.freewebs.com/mgsujith/worm/regedit_media/regedit.gif" alt="" width="640" height="480" /></p>
<p>Browse to <strong>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\</strong></p>
<blockquote>
<blockquote><p><strong> CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL</strong></p></blockquote>
</blockquote>
<p>Change the value of <strong>CheckedValue</strong> from 0 to <strong>1</strong></p>
<blockquote>
<blockquote><p><strong>Cleaning the pen drive right click options :</strong></p></blockquote>
</blockquote>
<p>Browse to <strong>HKEY_CURRENT_USER\Software\Microsoft\Windows\</strong></p>
<blockquote>
<blockquote><p><strong> CurrentVersion\Explorer\MountPoints2</strong></p></blockquote>
</blockquote>
<p>Delete all the long keys ( which look likeÂ  {DGF53-353b3gg3-353523-3g523g}Â  ) there.</p>
<p><strong>Still having problems with this &#8220;Orkut is banned&#8221; virus &#8221; ??</strong></p>
<p>First make sure that the virus is completely removed from the computer.</p>
<p>How to remove &#8220;Use Internet Explorer you dope, I dnt hate Mozilla but use IE`r OR ELSEâ€¦&#8221; svchost.exe heap41a virus<br />
<a onclick="return top.js.OpenExtLink(window,event,this)" rel="nofollow" href="http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/" target="_blank">http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/ </a></p>
<blockquote><p>Then go to :</p></blockquote>
<p><strong>Start &gt;Run &gt;</strong><br />
Type <strong>regedit</strong></p>
<p>Browse to <strong>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\</strong></p>
<p><strong> CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL</strong></p>
<p>Change the value of <strong>CheckedValue</strong> from 0 to <strong>1</strong></p>
<p>Take <strong>My Computer &gt; Tools &gt; Folder Options</strong></p>
<p>Change the setting to <strong>show hidden files and folders</strong></p>
<p>Apply and check again.</p>
<p>If it doesn&#8217;t work, there is another setting in the registry maybe in HKEY_USERS or HKEY_CURRENT_CONFIG or even HKEY_CURRENT_USER which overrides this setting.<br />
I&#8217;ll try to find out where it is (I came across such a problem earlier and I found that key by luck) The key is in a similar place like this \Software\Microsoft\Windows\ CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL</p>
<p>only that the beginning is different.</p>
<p>I&#8217;ll post it here when I find it. If anybody knows where it is, please do reply <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/#comment-146" target="_blank">http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/#comment-146 </a></p>
<p>It&#8217;s a relatively new virus, so most antivirus softwares are not able to detect and delete it.</p>
<p>To remove the virus completely, first you have to end the process svchost.exe belonging to the current user (i think you were able to do that and it worked). But then, the virus files are still hidden in your computer in two places.<br />
In C:\heap41a and in temporary folder.</p>
<p>A trick to get to these folders :</p>
<p><span style="font-weight: bold">Start &gt; Run<br />
</span>Type <span style="font-weight: bold">C:\heap41a </span>. Click<span style="font-weight: bold"> OK<br />
</span>Now, you should be able to see and delete the virus files</p>
<p>Second location (temporary files)<br />
<span style="font-weight: bold">Start &gt; Run<br />
</span>Type <span style="font-weight: bold">%temp% </span>. Click<span style="font-weight: bold"> OK<br />
</span>Here, you see the virus files it used to enter the computer.</p>
<h2 class="post-title"><a title="Permanent Link: Brontok virus - Green Background webpage with red text" rel="bookmark" href="../2007/04/brontok-virus-green-background-webpage-with-red-text/">Brontok virus &#8211; Green Background webpage with red text</a></h2>
<h2 class="post-title"><a title="Permanent Link: Harry Potter computer viruses - funny !" rel="bookmark" href="../2007/07/harry-potter-computer-viruses-funny/">Harry Potter computer viruses &#8211; funny !</a></h2>
<h2 class="post-title"><a title="Permanent Link: Hacked by MOOzilla - Autoplay on all drives - IISdll.dll.vbs virus" rel="bookmark" href="../2007/06/hacked-by-moozilla-autoplay-on-all-drives-iisdlldllvbs-virus/">Hacked by MOOzilla &#8211; Autoplay on all drives &#8211; IISdll.dll.vbs virus</a></h2>
<h2 class="post-title"><a title="Permanent Link: OfcpfSvcs.exe - virus or worm (or a harmless system file)" rel="bookmark" href="../2007/04/ofcpfsvcsexe-virus-or-worm-or-a-harmless-system-file/">OfcpfSvcs.exe &#8211; virus or worm (or a harmless system file)</a></h2>
]]></content:encoded>
			<wfw:commentRss>http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>How to remove &#8220;Use Internet Explorer you dope, I dnt hate Mozilla but use IE`r        OR ELSE&#8230;&#8221; svchost.exe heap41a virus</title>
		<link>http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/</link>
		<comments>http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/#comments</comments>
		<pubDate>Sat, 30 Jun 2007 16:06:28 +0000</pubDate>
		<dc:creator>FunDa</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[USB virus]]></category>
		<category><![CDATA[YouTube]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[ban]]></category>
		<category><![CDATA[heap41a]]></category>
		<category><![CDATA[orkut]]></category>
		<category><![CDATA[problems]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/</guid>
		<description><![CDATA[I just clicked the firefox shortcut on my desktop like I do any other day, when suddenly, a message box appears :
&#8220;USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE `r        OR ELSE&#8230;&#8221;
Another virus which wants to waste my time. I didn&#8217;t think hackers would write [...]]]></description>
			<content:encoded><![CDATA[<p>I just clicked the firefox shortcut on my desktop like I do any other day, when suddenly, a message box appears :</p>
<p>&#8220;<strong>USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE `r        OR ELSE&#8230;</strong>&#8221;</p>
<p>Another virus which wants to waste my time. I didn&#8217;t think hackers would write a virus to attack firefox. Anyway, I used Internet Explorer (IE means Internet Explorer) and typed in <strong>www.orkut.com</strong></p>
<p><img src="http://posso.files.wordpress.com/2007/09/worm_.jpg" alt="WORM" /></p>
<p>Yet another message &#8220;<strong>ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r                                               MUHAHAHA!!</strong>&#8221;</p>
<p>What about <strong>www.youtube.com ?</strong> That is banned too !!!</p>
<p>It&#8217;s just a worm, a virus or a trojan or whatever malicious hacker or craker program or script it is. Wrtitten is VBScript programming labguage by a crazy rascal who deserves to rot in his/her grave for <strong>disabling Firefox</strong> of all softwares !</p>
<p><strong> How to remove the Orkut and Firefox and Youtube banning virus ?</strong></p>
<p>Simple.</p>
<ul>
<li>First press Control-Alt-Delete (Ctrl-Alt-Del is called the <em>three finger exercise in Windows</em>)</li>
</ul>
<ul>
<li>There Click <strong>Processes</strong> , then click User Name to arrange according to users.</li>
</ul>
<ul>
<li>Now, look for svchost.exe run by User name &#8220;user&#8221; or &#8220;admin&#8221; or &#8220;your computer name&#8221; There will be two of them. Right click and end both the svchost.exe processes where the User Name is NOT &#8220;SYSTEM&#8221; or &#8220;NETWORK SERVICE&#8221; or &#8220;LOCAL SERVICE&#8221; Only where the user name is &#8220;USER&#8221; or &#8220;ADMIN&#8221; or &#8220;ADMINISTRATOR&#8221; or &#8220;your name&#8221;</li>
<li>Next Click <strong>Start &gt; Run &gt; </strong>Type cmd in the box and press enter (Just get the Command Prompt of DOS &#8211; C:\windows\system32\cmd.exe)</li>
<li>There in the black Command Line, type &#8220;<strong> cd \ </strong>&#8221; and press Enter</li>
<li>It has to change to <strong>C:\&gt;</strong></li>
<li>Next, type      <strong>attrib -s -r -h heap41a /s /d</strong> and press Enter</li>
<li>Then Open C: on My computer and <strong>delete the folder</strong> <strong>heap41a</strong> ie <strong>C:\heap41a</strong></li>
<li>Then remove <strong>C:\heap41a\svchost.exe shortcut</strong> from <strong>C:\Documents and Settings\USER\Start Menu\Programs\Startup (Or Start &gt; All Programs &gt;Startup)</strong></li>
<li>That&#8217;s all</li>
<li>Then clean the pen drive</li>
</ul>
<blockquote>
<blockquote>
<blockquote><p><strong>Cleaning the pen drive :</strong></p></blockquote>
</blockquote>
<ul>
<li>First make sure that the computer is clean (all viruses have been removed)</li>
<li>Plug in the pen driv, but make sure YOU <strong>DON&#8217;T DOUBLE CLICK </strong>on the pen drive icon in My Computer</li>
<li>Open <strong>My Computer</strong> . <strong>Right Click </strong>on the pen drive.</li>
<li>Click <strong>Search </strong>from the menu that appears ( <strong>Auto, Autoplay, Open (O)</strong>, all belong to the virus and clicking any of them will infect the computer with the virus again.</li>
<li>In Search <strong>All files and folders </strong></li>
<li>TypeÂ  &#8221; <strong>*.exe </strong>&#8221; (without the &#8221; &#8220;) in the first box (all or part of the filename)</li>
<li>Click <strong>More advanced options</strong> justabove the search button</li>
<li>Tick <strong>Search hidden files and folders   (* <a title="fix View hidden folders not working" href="http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/">see below </a>if this doesn&#8217;t work)<br />
</strong></li>
<li>Click <strong>Search </strong>button</li>
<li>In the files that come in the search results, look for files of the <em>Type</em> <strong>Application </strong>with the <strong>icon of a folder</strong></li>
<li>These .exe files are trying to disguise themselves as folders to fool you into clicking them, so the most probably are viruses !!!</li>
<li>Delete them (make a backup copy if required) and check the pen drive again.</li>
</ul>
</blockquote>
<blockquote></blockquote>
<blockquote><p>Sometimes, the virus would have disabled the showing hidden files option.</p></blockquote>
<blockquote></blockquote>
<blockquote><p>Here is how to fix that problem &#8211; an animated video tutorial</p></blockquote>
<blockquote>
<h2 class="post-title"><a title="Permanent Link: Show hidden files and folders not working - after virus attack (heap41a svchost.exe)" rel="bookmark" href="../2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/">Show hidden files and folders not working &#8211; after virus attack </a></h2>
<p>The above animated tutorial and youtube video will hep you to fix the problem of hidden and system files not being visible even after changing the setting it Folder Options. It happens because the virus locks a setting. The above link shows how to <a title="see hidden and system files again" href="http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/">change the setting</a> back.</p>
<h2 class="post-title"></h2>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.fundazone.com/2007/06/how-to-remove-use-internet-explorer-you-dope-i-dnt-hate-mozilla-but-use-ier-or-else-svchostexe-heap41a-virus/feed/</wfw:commentRss>
		<slash:comments>52</slash:comments>
		</item>
	</channel>
</rss>
