Is your computer infected with infamous Surabaya in my birthday virus? Need help to remove surbya virus, then follow these instructions to uninstall Surabaya in my Birthday virus. Delete W32/Drowor.worm and all of its components manually.
what is Surabaya in my birthday virus:
W32/Drowor.worm may get send around using a deceiving filename Google Earth .scr.
Displays this annoying alert message:
Surabaya in my birthday
Don’t kill me, i’m just send message from your computer
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti……

How to confirm weather your computer is infected with Surabaya in my birthday malware:
It modifies autoexec.bat to display a message upon system start: “Don’t kill me, i’m just send message from your computer”
your folder has file size 40K
Modified PE binary files
Once your system is infected with this virus, it will change the handling of windows explorer. You,ll be unable to open any partition of your hard disk, when you right click or left click on any partition, the autorun dialog box will appear instead of the partition.
The virus Surabaya-in-my-birthday will automatically hide your original files and folders and will place new folders with the same name but the new folders would be of 40 Kb only in size.
If you right click on any file, the menu which opens will show “test”, “configure”. etc options but no “open” option.
How to uninstall Surabaya in my birthday virus::
Follow the steps bwlot to delete surabya virus.
Go to Start Menu and open Run
type “cmd” and hit Enter
Type in command box- cd\
Type again in command box- c:
Type again in command box- attrib -s -h -r /d /s -> press Enter
Type again in command box- del autorun.inf -> press Enter
Type again in command box- del thumb*.* -> press Enter
Repeat the same with your other hard drive partitions as well…say if you have 3 drive partitions viz. “C”, ”D” & ”E”…for this:
Type again in command box- d:
Type again in command box- attrib -s -h -r /d /s -> press Enter
Type again in command box- del autorun.inf -> press Enter
Type again in command box- del thumb*.* -> press Enter
Type again in command box- e:
Type again in command box- attrib -s -h -r /d /s -> press Enter
Type again in command box- del autorun.inf -> press Enter
Type again in command box- del thumb*.* -> press Enter
If you have any USB hard drive on pen drive connected, do the above procedure with its drive name. For example if your USB drive name is “G”
Type again in command box- g:
Type again in command box- attrib -s -h -r /d /s -> press Enter
Type again in command box- del autorun.inf -> press Enter
Type again in command box- del thumb*.* -> press Enter
Type again in command box- exit
Step 2:
Go to Start then Run
type “regedit” and hit Enter
Brows the following
“HKEY_LOCAL_MACHINE”->“SOFTWARE” -> “Microsoft” -> “Windows NT” -> “Current Version” -> “WinLogon”.
Now on the right side window (under data) delete “LegalNoticeCaption” & “LegalNoticeText”.
Step 3:
Go to Start menu -> Programs -> Accessories -> System Tools -> System restore
This’ll open a box where you’ll get the option – “Restore my system to an earlier time”… Select any old date on which you think your system was working fine…push on next..next…till the system restore starts…
System restore takes a few minutes to complete depending on your computer speed….so be patient….after system restore completes….Your computer will restart…..the problem should have been solved.
Step 4:
Press Start -> Run -> regedit ->press Enter
Press Ctrl + F
In the find window type Surabaya if at all you find any entries in the registry with this name…”Surabaya”…delete them
Step 5:
This virus makes your system’s show hidden file option in folder menu to get disabled. To make your computer to show Hidden files, and to get your computer again back into normalcy…
Start — Run — regedit — OK
HKEY_LOCAL_MACHINE -> Software -> Microsoft -> Windows ->
Current Version -> Explorer -> Advanced -> Folder -> Hidden -> Show All
On the right side window, locate this: CheckedValue = “0″
Modify this value to 1. (right click on the Checked value under Name column -> Modify)
Note:
This virus usually reaches to your computer through any USB drive (pen drive or hard disc). Whenever you plug your USB drive into any other computer, infected with this virus, the virus will infect this drive and will infect the next computer, in which the drive is plugged in next time. So its always advisable not to open the pen drive directly. Instead always right click on the drive and select open option. If at all you see the first option as “autorun”, after you right click on the USB drive, this means that the drive is infected.
Auto Removal
To remove this virus Automatically, We suggest following tools:
Malware Bytes Anti-Malware (Download)
HitMan Pro Anti-Malware (Download)

does this work for windows 7 as well? Or is there another way?
Give it a try,
Most windows xp tools and commands are found working well with windows 7
When i tried Step 1. It says “Access denied”. What will i do? please help.
@ Garcia, you may try the auto removal tools