How to remove Heap41a/win32.USBworm


I learnt about this worm few days ago when it first infected my father's laptop and has recently infected this PC too. This worm pissed me off for a number of reasons. First, it blocked me from using my favorite browser, Firefox. Fair enough, it must be an IE fan who can not accept the fact that Firefox is taking popularity off of Internet Explorer BUT blocking me from enjoying Youtube videos is something that cannot be tolerated. If you got the following message, then you too has the same problem.

I Dnt Hate Mozilla But Use IE Or Else... with title as Use Internet Explorer U Dope.

I'm quite convenient of sorting this out manually primarily because it doesn't require me to change to Avast just for the sake of removing this worm (wow, this worm circumvents my AVG anti virus). Ok, here is the steps needed to remove it completely from your computer.

First solution

  1. Press CTRL+ALT+DEL to open Windows task Manager.
  2. Go to the processes tab and look for svchost.exe under the "image name". There will be many but look for the ones which have your username under the "username".
  3. Press DEL to kill these files. It will give you a warning, simply press Yes
  4. Repeat for other svchost.exe files with your username. Note: Do not kill svchost.exe under system, local service or network service.
  5. Type C:\heap41a in Start Menu > run.. and press enter. You need to do this because it is a hidden folder.
  6. Delete all files inside this folder.
  7. Again go to Start Menu > Run and type in Regedit
  8. Go to the menu Edit > Find
  9. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
  10. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
  11. Now close the registry editor and you are done.

Make sure to delete the autorun.inf file and any unrecognized file ends with .exe in your pen drive otherwise it will replicate itself again.

Second solution

Do the steps look creepy for you to try? Ok, here's another solution made by sarathlakshman. Download this file, unzip it, run the program and press the remove button. Done! :)

via MgHarish

Technorati Tags: , ,




If you find this page useful, you might want to subscribe to this site via the RSS feed or email subscription.
Comments
  1. uzair says on September 11, 2007 at 5:07 am

    Thanks Eches..now i know how to remove it permanently..

  2. sanjoy debanath says on September 13, 2007 at 9:14 am

    Thank .. thanks a lot for the solution.

    It save my PC finally.

  3. swaroop says on September 24, 2007 at 11:32 am

    Hi eches…
    thanks a lot for your suggestion….
    it really worked for me.
    thanks buddy..
    swaroop

  4. eches says on September 24, 2007 at 6:54 pm

    Glad to hear that it works :)

  5. DJ Varun says on October 30, 2007 at 2:34 am

    well guys.. i found a very simple way.. to delete the worm

    go to run.. type c:\heap41a
    or in my computer address bar type c:\heap41a
    make a new folder in the same folder
    simply cut all the files and paste it in the new folder…

    restart your system and its gone..

    run some worm utility later to clean it up completely

  6. Pingback: Eches » Blog Archive » Deep Freeze: Keep all malicious viruses/worms at bay

  7. rishi says on November 11, 2007 at 2:33 am

    the procedure is good thanks buddy

  8. Vikas says on November 20, 2007 at 8:59 pm

    Thanks a lot, kudos to you people

  9. rahul says on December 30, 2007 at 2:46 pm

    THANKS A LOT IT WORKED FOR ME

    THANKSSSSSSSSS!!!!!!!

  10. sony says on January 7, 2008 at 12:34 pm

    Thanks alot for the solution……..

  11. iskwan says on January 21, 2008 at 11:28 pm

    thanks a lot

  12. Aishah says on February 21, 2008 at 12:33 pm

    Thanks a lot..I get to go to IMEEM.com again!!!

  13. naga prasad says on March 14, 2008 at 7:56 pm

    I downloaded as per the instructions but still it did not allow me to open the orkut.still i have the heap41a virus left on my system.

  14. Murali says on May 29, 2008 at 1:35 am

    Thanks a ton it resolve my problem.

  15. Mark Greyvenstein says on June 17, 2008 at 7:24 pm

    Thanks a Million this work really started peeing me off terribly. But thanks to your help I think it is gone now. Thank you again.

  16. naveen says on June 21, 2008 at 8:17 pm

    VERY THANX TO U………

  17. Binoy says on July 29, 2008 at 2:29 pm

    Thanks a lot . its worked fine

  18. eches says on July 29, 2008 at 9:35 pm

    Glad to hear that :)

  19. selvakumar says on August 3, 2008 at 12:34 pm

    SUper it is working in fantastic manner.
    thanks for this solution.
    Your service will be good to this world.
    Keep up this good work.
    Living for others is a great thing.

  20. hari says on August 4, 2008 at 10:20 pm

    hi dear,
    i think u r genious than the one who write the fix
    i downloaded two solution fixes but they dont work for me
    then i try your bug but cannot found heap… file.but i identify that in some systems it has the name win32.usbworm any i am really thankfull to you mate
    expecting more informations from you

  21. eches says on August 5, 2008 at 2:58 am

    Thanks guys. I’m glad they work for you :)

  22. Pingback: How to remove fake Antivirus 2008

  23. Pingback: How to remove fake Antivirus 2008

  24. Ravi says on August 31, 2008 at 1:21 pm

    thanks a lot………..

  25. Mario says on October 30, 2008 at 11:38 pm

    Thanks mate, you saved my day. It really worked for me.
    Thanks a million.

  26. jimish says on December 5, 2008 at 4:47 pm

    when ever i try to start task manager i get message “SORRY” from SAM .. i tried to find the folder you informed heap41a but cannot find it they way you infomr … inform what should be done now

  27. shine says on February 4, 2009 at 5:02 pm

    great!

  28. Petrus Brasilis says on February 27, 2009 at 9:35 am

    Parabens pelo fantastico trabalho desenvolvido em favor dos usuarios da WWW. Que recompensas mil possam ser colhidas por essa equipe de verdadeiros cientistas sociais que nao medem esforcos para construir um mundo melhor. Deus abencoe e capacite a cada dia mais e recompense todo esse trabalho sensacional. Um abracao do Brasil.

  29. Pingback: Prevent Autorun.inf Infection with Panda USB AutoRun Vaccine

  30. vivek says on March 28, 2009 at 1:25 am

    thanks a lot dude.
    your suggestion was simple,procedural and adequate.
    i would have deleted so many other files for the fear of this file.
    thanks.

  31. Pingback: Prevent Autorun.inf Infection with Panda USB AutoRun Vaccine | Stumbled

  32. Shanu says on April 13, 2009 at 1:41 pm

    Thanks, wonderful , its working well.
    Thank u again for the help…..

    Regards,
    Shanavas

  33. k.v.vnayak says on June 22, 2009 at 9:54 pm

    thanks for the tip and remover software
    really helpfull

  34. JP says on July 16, 2009 at 9:51 pm

    Thank’s, it was bugging me ;)

  35. SerSinism says on August 21, 2009 at 2:56 pm

    ohh!! thanx alot..your solution was so wonderful..thanx again

  36. Arindam Dey says on October 29, 2009 at 4:17 pm

    Thanks buddy…procedure was simply good and it helped me a lot

Leave your comment