feedburner
Enter your email address:

Delivered by FeedBurner

feedburner count
Sep
10th

How to remove Heap41a/win32.USBworm

Author: eches | Files under Security, Tips & Tricks

I learnt about this worm few days ago when it first infected my father's laptop and has recently infected this PC too. This worm pissed me off for a number of reasons. First, it blocked me from using my favorite browser, Firefox. Fair enough, it must be an IE fan who can not accept the fact that Firefox is taking popularity off of Internet Explorer BUT blocking me from enjoying Youtube videos is something that cannot be tolerated. If you got the following message, then you too has the same problem.

I Dnt Hate Mozilla But Use IE Or Else... with title as Use Internet Explorer U Dope.

I'm quite convenient of sorting this out manually primarily because it doesn't require me to change to Avast just for the sake of removing this worm (wow, this worm circumvents my AVG anti virus). Ok, here is the steps needed to remove it completely from your computer.

First solution

  1. Press CTRL+ALT+DEL to open Windows task Manager.
  2. Go to the processes tab and look for svchost.exe under the "image name". There will be many but look for the ones which have your username under the "username".
  3. Press DEL to kill these files. It will give you a warning, simply press Yes
  4. Repeat for other svchost.exe files with your username. Note: Do not kill svchost.exe under system, local service or network service.
  5. Type C:\heap41a in Start Menu > run.. and press enter. You need to do this because it is a hidden folder.
  6. Delete all files inside this folder.
  7. Again go to Start Menu > Run and type in Regedit
  8. Go to the menu Edit > Find
  9. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
  10. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
  11. Now close the registry editor and you are done.

Make sure to delete the autorun.inf file and any unrecognized file ends with .exe in your pen drive otherwise it will replicate itself again.

Second solution

Do the steps look creepy for you to try? Ok, here's another solution made by sarathlakshman. Download this file, unzip it, run the program and press the remove button. Done! :)

via MgHarish

Technorati Tags: , ,


AddThis Feed Button Bookmark and Share


Related Posts

» How to remove fake Antivirus 2008
» A-Patch for Windows Live Messenger (WLM) 9.0
» Remove PDF restriction with PDF Unlocker
» How to uninstall Windows Media Player 11

Related References

25 responses. Wanna say something?

  1. uzair
    Sep 11, 2007 at 05:07:54
    #1

    Thanks Eches..now i know how to remove it permanently..

  2. sanjoy debanath
    Sep 13, 2007 at 09:14:50
    #2

    Thank .. thanks a lot for the solution.

    It save my PC finally.

  3. swaroop
    Sep 24, 2007 at 11:32:37
    #3

    Hi eches…
    thanks a lot for your suggestion….
    it really worked for me.
    thanks buddy..
    swaroop

  4. eches
    Sep 24, 2007 at 18:54:53
    #4

    Glad to hear that it works :)

  5. DJ Varun
    Oct 30, 2007 at 02:34:02
    #5

    well guys.. i found a very simple way.. to delete the worm

    go to run.. type c:\heap41a
    or in my computer address bar type c:\heap41a
    make a new folder in the same folder
    simply cut all the files and paste it in the new folder…

    restart your system and its gone..

    run some worm utility later to clean it up completely

  6. rishi
    Nov 11, 2007 at 02:33:47
    #6

    the procedure is good thanks buddy

  7. Vikas
    Nov 20, 2007 at 20:59:16
    #7

    Thanks a lot, kudos to you people

  8. rahul
    Dec 30, 2007 at 14:46:29
    #8

    THANKS A LOT IT WORKED FOR ME

    THANKSSSSSSSSS!!!!!!!

  9. sony
    Jan 7, 2008 at 12:34:46
    #9

    Thanks alot for the solution……..

  10. iskwan
    Jan 21, 2008 at 23:28:19
    #10

    thanks a lot

  11. Aishah
    Feb 21, 2008 at 12:33:30
    #11

    Thanks a lot..I get to go to IMEEM.com again!!!

  12. naga prasad
    Mar 14, 2008 at 19:56:48
    #12

    I downloaded as per the instructions but still it did not allow me to open the orkut.still i have the heap41a virus left on my system.

  13. Murali
    May 29, 2008 at 01:35:31
    #13

    Thanks a ton it resolve my problem.

  14. Mark Greyvenstein
    Jun 17, 2008 at 19:24:51
    #14

    Thanks a Million this work really started peeing me off terribly. But thanks to your help I think it is gone now. Thank you again.

  15. naveen
    Jun 21, 2008 at 20:17:52
    #15

    VERY THANX TO U………

  16. Binoy
    Jul 29, 2008 at 14:29:04
    #16

    Thanks a lot . its worked fine

  17. eches
    Jul 29, 2008 at 21:35:38
    #17

    Glad to hear that :)

  18. selvakumar
    Aug 3, 2008 at 12:34:04
    #18

    SUper it is working in fantastic manner.
    thanks for this solution.
    Your service will be good to this world.
    Keep up this good work.
    Living for others is a great thing.

  19. hari
    Aug 4, 2008 at 22:20:49
    #19

    hi dear,
    i think u r genious than the one who write the fix
    i downloaded two solution fixes but they dont work for me
    then i try your bug but cannot found heap… file.but i identify that in some systems it has the name win32.usbworm any i am really thankfull to you mate
    expecting more informations from you

  20. eches
    Aug 5, 2008 at 02:58:58
    #20

    Thanks guys. I’m glad they work for you :)

  21. Ravi
    Aug 31, 2008 at 13:21:18
    #21

    thanks a lot………..

  22. Mario
    Oct 30, 2008 at 23:38:58
    #22

    Thanks mate, you saved my day. It really worked for me.
    Thanks a million.

3 Trackback(s)

  1. Oct 30, 2007: Eches » Blog Archive » Deep Freeze: Keep all malicious viruses/worms at bay
  2. Aug 6, 2008: How to remove fake Antivirus 2008
  3. Aug 6, 2008: How to remove fake Antivirus 2008

Post a Comment

site statistics