New Threat, My_Heart.exe

A friend of mine informed me there is a new virus spreading around which is known as My_Heart.exe (please this is not the famous Indonesian song). Actually he knew about it after the virus messed up his system. According to him, when he double clicked the certain folder – it will close the window and back to the desktop. He using F-Secure antivirus software and he said he faced difficulties to update the antivirus in online because when did like that the antivirus software shutdown.

After done few investigation, I soon found out that My_Heart.exe is actually might be a malicious VBS Script just like the Fucker.vbs and autoupdate.dll.vbs which was terrorized the PC couple of months back. The file is located in Windows>System32 folder which can manually be deleted as well its startup files. As my friend said after he updated his antivirus software’s virus database the threat seems disposed. So, just make sure update your antivirus and it will take care of your PC.

Last but not least, the infected thumb drive can’t even open when right click open or explore – I have to use the command prompt to delete the autorun.inf file and then only can open the thumb drive. Well, that’s the only information I knew so be alerted.

I manage to found out an official documentation about this script which categorized as worm.

Kindly head to Sophos

2 comments:

Anonymous said...

i've encountered this threat in my bro's pendrive. When the virus has infected the pendrive, it creates an autorun.inf file, so whenever you click to open you pendrive, it automatically runs a new copy of the program on the background. Each copy takes up about 3-5 MB of memory.
It will also infect your Windows files, and some files in the user's documents and settings. It will replicate to run many copies simultaneously thus hogging ur memory.
You can remove it by running a search for "My_Heart.exe" and delete them manually. It worked for me. Remember to enable searching for hidden files.

k3sh said...

Hmm ok thats explains how it works.sounds like New Folder.exe breed..yup jus delete the file in system32 will work as well the startup files..