Sat 30 Jun 2007
How to remove “Use Internet Explorer you dope, I dnt hate Mozilla but use IE`r OR ELSE…” svchost.exe heap41a virus
Posted by FunDa under Firefox , Internet Explorer , USB virus , YouTube , antivirus , ban , heap41a , orkut , problems , wormI just clicked the firefox shortcut on my desktop like I do any other day, when suddenly, a message box appears :
“USE INTERNET EXPLORER YOU DOPE,I DNT HATE MOZILLA BUT USE IE `r OR ELSE…”
Another virus which wants to waste my time. I didn’t think hackers would write a virus to attack firefox. Anyway, I used Internet Explorer (IE means Internet Explorer) and typed in www.orkut.com

Yet another message “ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r MUHAHAHA!!”
What about www.youtube.com ? That is banned too !!!
It’s just a worm, a virus or a trojan or whatever malicious hacker or craker program or script it is. Wrtitten is VBScript programming labguage by a crazy rascal who deserves to rot in his/her grave for disabling Firefox of all softwares !
How to remove the Orkut and Firefox and Youtube banning virus ?
Simple.
- First press Control-Alt-Delete (Ctrl-Alt-Del is called the three finger exercise in Windows)
- There Click Processes , then click User Name to arrange according to users.
- Now, look for svchost.exe run by User name “user” or “admin” or “your computer name” There will be two of them. Right click and end both the svchost.exe processes where the User Name is NOT “SYSTEM” or “NETWORK SERVICE” or “LOCAL SERVICE” Only where the user name is “USER” or “ADMIN” or “ADMINISTRATOR” or “your name”
- Next Click Start > Run > Type cmd in the box and press enter (Just get the Command Prompt of DOS - C:\windows\system32\cmd.exe)
- There in the black Command Line, type “ cd \ ” and press Enter
- It has to change to C:\>
- Next, type attrib -s -r -h heap41a /s /d and press Enter
- Then Open C: on My computer and delete the folder heap41a ie C:\heap41a
- Then remove C:\heap41a\svchost.exe shortcut from C:\Documents and Settings\USER\Start Menu\Programs\Startup (Or Start > All Programs >Startup)
- That’s all
- Then clean the pen drive
Cleaning the pen drive :
- First make sure that the computer is clean (all viruses have been removed)
- Plug in the pen driv, but make sure YOU DON’T DOUBLE CLICK on the pen drive icon in My Computer
- Open My Computer . Right Click on the pen drive.
- Click Search from the menu that appears ( Auto, Autoplay, Open (O), all belong to the virus and clicking any of them will infect the computer with the virus again.
- In Search All files and folders
- Type ” *.exe ” (without the ” “) in the first box (all or part of the filename)
- Click More advanced options justabove the search button
- Tick Search hidden files and folders
- Click Search button
- In the files that come in the search results, look for files of the Type Application with the icon of a folder
- These .exe files are trying to disguise themselves as folders to fool you into clicking them, so the most probably are viruses !!!
- Delete them (make a backup copy if required) and check the pen drive again.
June 30th, 2007 at 10:40 pm
Man what kind of anti virus are you using? Cos sounds to me like it’s not doing a very good job. Maybe it’s time you tried something else.
BTW how do I add these code boxes above the comment box; b,i,link,b-quote… etc…let me know in a mail ok
September 5th, 2007 at 6:23 pm
hey!
your method worked! and it was really easy to follow especially for a computer illiterate like me =) thank you!
September 9th, 2007 at 1:33 pm
Hey john,
everythin went well until step 7 .. tried deleting the heap41 from c: but then i get this : ” cannot delete svchost.exe: access is denied. make sure the disk is not full or write-protected and that the file is not currently in use.”
er.. wht do i do now???
September 9th, 2007 at 1:45 pm
hey john.. got it rite..
thnx mate!! u rock
September 10th, 2007 at 1:44 pm
U r welcome !!!
Just remember that there are usually two svchost.exe that u have to “End Process”
Unless both are ended (killed), U will get this message : ” cannot delete svchost.exe: access is denied. make sure the disk is not full or write-protected and that the file is not currently in use.”
September 13th, 2007 at 12:34 pm
Hey. Nice procedure explained. But I have a problem. I am unable to see hidden files even after going thru the folder options procedure. Please help !
September 13th, 2007 at 7:55 pm
Hi..
I followed your instructions correctly but at step 7, i get a message saying ‘file not found’. Both Mozilla Firefox and Orkut work fine until i switch off my comp and restart it. Then the same problem recurs.
Can you help me with this please?
Thanks…
Vinod
September 16th, 2007 at 1:48 pm
Thank you! Your suggestions worked and my Firefox is up and running again. Thanks for sharing.
September 18th, 2007 at 11:03 am
Ados:
Try this page - to repair View hidden files and ders option
Make hidden files and folders visible ( http://www.fundazone.com/2007/09/show-hidden-files-and-folders-not-working-after-virus-attack-heap41a-svchostexe/ )
The virus changes some registry settings which have to be brought back to normal for the setting to work properly.
September 28th, 2007 at 1:08 pm
As per ur suggestions, wen i open the task manager, i get ‘task manager has been disabled by ur administrator’ wat should i do?
September 28th, 2007 at 2:37 pm
This is caused by a virus called sscvihost.exe or rvhost.exe
To get Task Manager back,
* Download “Process Explorer”
* Run “Process Explorer” and kill process “SSCVIHOST” (2 copies)
* Delete the virus file from C:\windows\sscvihost.exe
* Run these 3 commands from Start > Run or from Command Prompt
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 0 /f
October 4th, 2007 at 12:29 am
Thank u very much. I am able to work on mozilla again.
Is there any free anti virus program, that keeps this thing blocked from my system?
October 10th, 2007 at 10:15 pm
thank u dude
ure my saviour
thanx
i am really a comp illiterate
u make my day
October 14th, 2007 at 9:36 am
Hey!
Just wanted to thank you for sharing so freely… would have been very difficult for me to figure a way out of this problem if i hadn’t come across your blog. Mozilla Firefox and Orkut are running fine on my computer now. Thanks a TON, buddy!
Take care..
Vinod
October 15th, 2007 at 3:05 pm
tnks a lot its workin i removed dat bloody………
October 16th, 2007 at 11:45 pm
hey!
thanks!
i’d already tried to get rid of this virus 2 other ways, and was just not working. actually it did work, but each time i restarted my computer it would be back!
thanks! really liked the explanation.. step-by-step!
October 22nd, 2007 at 4:56 am
you rock man..thanks
December 7th, 2007 at 12:34 pm
damed,dint work seems the virus is deadly!! Its says its not in the process. wat do i do next dude..help.
December 18th, 2007 at 7:58 pm
thanks..
its work…
thanks again…
December 23rd, 2007 at 10:59 pm
Hey i have tried ur formula, bt when i go to ” C:\> ” and when i write ” attrib -s -r -h heap41a /s /d ” and press Enter it shows that ” it is not recognized as an internal or external command, operable program or batch file. ” and i also dont have any folder in C:\ Plzzzzz help me out plzzz plzzzzz tel me what should i do…
December 23rd, 2007 at 11:12 pm
Hey ur formula is helping me but, till i delete the folder from C:\ but i dnt found anythin in ” C:\Documents and Settings\USER\Start Menu\Programs\Startup ” i wan’t to tell u dat i have only 3 files there, 1 is ” hp psc 1000 series” 2 is ” hpoddt01.exe” and 3 is ” Microsoft Office ” now plz help me again, wat should i do now…
December 25th, 2007 at 9:53 pm
Thank’s
It’s work
Merry X-Mas
December 29th, 2007 at 4:29 pm
my problem is as same as mohit’s..
when i type the given code in the command prompt it says that “it is not regognized as as internal or external command,operable program or batch file”
what should i do now??
please help me!!
January 5th, 2008 at 10:43 pm
Thank you SO much for this.
I’ve just screamed my lungs out at my mum and sister for screwing up the PC, and you just helped me out of a very sticky situation
February 9th, 2008 at 11:41 pm
Dear sir,
As above stated i did. then also am unable to open OKRUT and others
please sugest me.
February 10th, 2008 at 12:04 am
as above i tryed and delet the file some days ago. and i tryed orkut its work.
after five day i didn’t go to orkut
againe its previous problem like okrut has banned.
i tryed as five days before i did but in CMD
am unablel to get the file and its showing file not found
please do the needful so that i can make my day end with joyfully.
please sugest me how to move on this problem.
February 20th, 2008 at 1:51 pm
Hi,
It worked well. Thanks :). I couldnot find heap41a. Well, can you let me know how one can write that sort of worm or virus? You told it was a VBScript. Can you mail me the script or the process to do that?
Thanks in advance.
March 1st, 2008 at 7:26 pm
hey there, thanks for the tip. i managed to removed the ******* thing. great job.
March 2nd, 2008 at 1:56 pm
@Srikanth
Please … don’t create viruses. make some useful program. there are lots of tutorials online for learning programmming.
Try going through w3c Schools. Or any other Tutorial site for Javascript, VBScript, PHP, HTML, Flash(Actionscript).
These viruses are bad, creating unnecessary problems and should be eliminated.
March 8th, 2008 at 6:41 am
hey,
can u let me know wat is the virus tat is affecting me
im unnable to open yahoomessenger and when i am opening other drive a new window is being displaced even if i have changed the properties in tools.
plz .. help
March 17th, 2008 at 11:06 pm
hey thanks for posting this really useful piece of info….it worked perfetly for me…..
March 19th, 2008 at 9:19 am
Thanks heaps!
you’re a legend!
March 25th, 2008 at 7:30 pm
> It’s just a worm, a virus or a trojan or
> whatever malicious hacker or craker
old issue, but hackers and crackers aren’t the same thing and hackers don’t cause you problems.
April 2nd, 2008 at 11:16 am
It did work. Many thanks!
April 30th, 2008 at 9:14 am
Thanks fo the help, I went through the stages, but get to the bit after typing in attrib… and it says its not recognized as an internal or external command, then I go to my computer, C and there is no file of that name…. please help, I want to use mozilla again!
May 3rd, 2008 at 7:25 am
Thanks a lot~
May 27th, 2008 at 7:22 pm
Thank you.
My children were innoculated against many diseases before going to school, but their pen drives weren’t. Your step by step approach was very easy to follow.
June 19th, 2008 at 9:46 am
man its really working my many many thanx is with this website………
July 10th, 2008 at 9:15 am
hey…. followed the thread… got rid of the worm. very much able to use mozilla, orkut n youtube….
but, there are still 2 problems am facing rite now–
1. am not able to open my C drive watever i do. it just refuses to open even with a right click. am able to access the files under it through Search though….
2. am still not able to get my Task Manager back…i followed the downloading the Process Explorer instruction… but still- Zilch…
need help…
July 12th, 2008 at 7:27 am
How do you even get it?
July 29th, 2008 at 6:35 pm
I would like to know the name of this Worm, Virus
~Aditya
July 31st, 2008 at 11:37 am
i could not find this folder in c drive heap41a. so plz tell me any other procissor to solve this problem.
July 31st, 2008 at 11:41 am
i have done it with ur help thank u so mauch
August 10th, 2008 at 9:34 pm
dude ur one brilliant guy…. i want to knw abt wher u learn such stuff…mail me… n thanks a ton!