Solution:
Step 1: Open Task Manager
–> Processes –> Find svchost.exe under the user account (There
will be others under network and system accounts. Don’t close them).
There will be two svchost.exe under the user account. Kill both of them.
Step 2: Then go
to Start –> Run –> regedit. A Registry Editor Window opens. Find the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Delete Winlogon key from the right hand pane.
Step 3: Enable your “Show
hidden files and folders”
Step 4:After completing Step 3, issue the following commands from the
command prompt:
Open command prompt and execute the following command:
attrib -S -H -R C:\heap41a
After executing the above command, execute the
following command:
rmdir /s /q C:\heap41a
Replace C:\ with your
system drive.
Step 5: If you are using a Pen drive, remove microsoftpowerpoint.exe
and autorun.inf from the drive.
Step 6: Go to your start menu –> All Programs –>
Startup. Make sure there is no unnamed suspicious file in the startup
folder.
Step 7: Turn off
system restore and turn it on again.
Step 8: Restart your computer.
Orkut Is Banned - Heap41a -
win32.USBworm Removal