I dnt hate Mozilla but use IE or else….

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
The above line is what I got when I tried to start Firefox sometime back. Just as the window opened, a box with this message popped up and then disappeared, taking my Firefox window along with it. Internet Explorer seemed to work until I tried opening Youtube. Then, I got the following message before IE shut down as well.
‘Youtube is banned you fool, The administrators didn't write this program guess who did?? MUHAHAHA!!'
I couldn't for the life of me figure out how this had happened so I decided to search and see if this problem had cropped up somewhere else. Turns out, it's pretty common. These messages are courtesy of the W32.USB worm. This worm copies itself to removable drives as Microsoft Power Point.exe and will infect your PC when you connect the infected drive to it. The infection is via a hidden Autorun.inf file.
use-ie.png

Luckily, it's fairly easy to get your browsers back to normal. Just follow the following steps.
  1. Right click the system tray and select the ‘Task Manager' or just hit ‘Ctrl+Alt+Del'. Once the task manager is open, navigate to the ‘Processes' tab.
  2. Under the ‘Image name' column, look for all entries marked ‘svchost.exe', which are running under your USERNAME ONLY (not system, local or anything else). Terminate these processes by hitting the ‘End Process' button. Close the task manager.
  3. The next step is to delete the files itself. Open ‘My Computer' and type ‘C:\heap41a', then hit Enter. The folder will have the files ‘svchost.exe, script1.txt, standard.txt, reproduce.txt, and an audio file.' Delete all the files in the folder and then delete the heap41a folder itself.
  4. Now we have to delete the registry entry as well. Go to ‘Start –> Run' and type ‘regedit'. Once the registry opens, on the menu bar, go to ‘Edit –> Find' and type ‘heap41a'. After searching, you should have some entries with ‘heap41a' in them. Delete all these entries.
  5. Your PC is free of the worm.
However, you also need to get rid of the worm from the USB drive, lest it infect your computer again. Connect your drive to the computer's USB port (disable the drive from auto playing) and delete all entries marked with ‘autorun'. They may sometimes be in a separate folder. Once these entries are gone, your USB drive is clean as well.
 
Status
Not open for further replies.
Back
Top Bottom