USBWorm: The Virus that prevents Firefox from running and hides all hidden files
Print This Post
I’ve recently encountered a severe Virus (or should we say, a Worm) called USBWorm. It doesn’t actually destroy any files or cause anything else to crash. But it does the major damage to the User activity.
First of all, let me tell you what happens when this worm has affected your system from any of your friend’s USB Flash Drives or USB Sticks.
- It hides all the hidden files in the System and won’t allow you to select Show hidden files and folders from the Tools -> Folder Options dialog.
- It shows a dialog whenever you tried to run any of Mozilla products after closing them shortly that has the Title: USE IE DOPE! with the Message: I DDNT HATE MOZILLA BUT USE IE OR ELSE…
- Whenever you tried to browse the websites Orkut and YouTube (even from IE) your browser will be closed immediately and a message is shown as: Orkut is banned you fool. The Administrators didn’t write this program guess who did? Mahahahaa. And it also plays a sound that is of evil nature.
So, how to remove this one? That’s the problem! No Internet Security or Antivirus Product as of now neither detects nor removes this Worm from your system. So, I’ve been very much frustrated and searched in google for the Worm name and found nothing. At last, I’ve tried this keyword: Virus prevents Mozilla and got the first hit that explained me all I need to know about this Worm and it’s ways of removal. You can find that one here.
But the problem is the fixing methods shown in the above site didn’t worked perfectly well so, I’ve decided to provide you the much detailed way in which I’ve successfully eliminated this virus.
- Get HiJackThis! (it’s free)
- Run this Program and click on the Do the Scan only button and then immediately navigate to the list item that says “O4 - HKLM\..\Policies\Explorer\Run: [winlogon] C:\heap41a\svchost.exe C:\heap41a\std.txt” and check the box near it and click on Fix Checked button from the left bottom corner. Don’t close the Dialog yet.
- Open Task Manager by right clicking on the Task Bar and choosing Task Manager or pressing Ctrl + Alt + Del.
- End the Processes that says svchost.exe in your Computer User Name (Please NOTE that only end the processes that says your computer user name, not the ones that says SYSTEM or NETWORK SERVICE)
- Go back to HiJackThis! and click on the Main Menu button in the bottom center. Again, go through the step 2.
- Now, close Task Manager and HiJackThis!. Go to Start -> Run and type: C:\Heap41a. Once inside this, delete all the contents of this folder with Shift + Delete button. (i.e. Don’t send them to Recycle Bin)
- If you face Access Denied in the above folder when you try to delete something, use the utility called Unlocker which is available for free. After installing Unlocker, just select the files and folders and right click on them and choose Unlocker which opens a dialog in which select Delete as the action and click on the Unlock All button.
- After the folder is successfully deleted, restart your system and voila, this Problem is gone for ever.
- Just be careful before inserting any USB Drives given by your friends as none of your Antivirus products will detect it (as of now, I think BitDefender detects it though but still it can’t remove it).
Edit [17th July 2007]
If you are still not able to view the hidden files and folders, please follow the method below to restore that functionality:
- Open Start Menu -> Run and type REGEDIT and press Enter
- In the Registry Editor, navigate to My Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL - Change the keys CheckedValue and DefaultValue to 1 (Double click on them to Edit)
- Close the Registry Editor and Open Windows Explorer by pressing Windows Key + E
- Open Tools -> Folder Options and select View tab and check the Show all files and folders under Hidden files and folders option.
- You’re Done!
Let me know your comments and suggestions…
You might’ve heard about
Are you tired of
A resident of Visakhapatnam, Tamil Nadu, INDIA has lost not one not two but thirty mobiles.
I’ve recently encountered a problem when I tried to manage both of my GoogleTalk (GTalk) ID’s (aspauljoseph, sapauljoseph). Not able to login in both of them at the same time. Either I need to use GoogleTalk for one and Gmail for another. Now, while googling, I found a nice solution that easily met my requirements.
I’ve recently got an invitation from my close friend
Hitachi Global Storage Technologies is the first to make our dream come true. I’ve always thought with this much of speedy increments in the storage space of a Hard Drive, it’ll be very soon when we had 1 Tera Byte storage capacity drives. Now, that thought came true very soon.
I hope you all remember I’m hosting my Servers with DreamHost, the BEST hosting providers in this planet. As a New Year 2007’s Gift, I wish to give you all a PromoCode that I created for New Year festival which you can apply when you order anything from DreamHost. This PromoCode will entitle you for a 10% discount of whatever you Order on DreamHost. Please NOTE that this is NOT provided by DreamHost. As their valued Partner and your Friend, I’m providing this Gift to you. You can ONLY get a deduction of 10% on your order when you apply this PromoCode.