Fandom

Malware Wiki

Heap41A

1,335pages on
this wiki
Add New Page
Comments0 Share

Heap41A is a harmful (depending on how you look at it) worm that prevents execution of Firefox.

Payload

After completing the spreading routine, the worm will prevent access to Firefox. Anything linked to Firefox, including the installer, will be closed with the following Windows message.

USE INTERNET EXPLORER YOU DOPE 
I DNT HATE MOZILLA BUT USE IE OR ELSE...

The solution to this would be simple, just use Internet Explorer. However, the worm has added a list of blacklisted domains, which are all legit websites.

www.youtube.com
www.orkut.com

Trying to access these domains will display the following message and play a sound bite through the computer speakers.

<youtube/ORKUT> IS BANNED
<youtube/Orkut> is banned you fool,The administrators didnt write this program guess who did??
MUHAHAHA!!

(All grammar mistakes are in-tact)

It will run in Task Manager as svchost under your Username. You can easily kill this process.

This virus also affects Google Chrome, it simply doesn't allow you to access the blacklisted domains.

Spreading Routine

Once executed as "MicrosoftPowerPoint.exe" (the real executable name is POWERPNT.EXE), it will drop an autorun.inf file and a copy of itself to all drives on the system. Whenever the infected drives are installed onto another system, the worm will activate on that computer.

Media

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.