How to kill Vlove virus
The Vietnamese Internet community is witnessing a new 'flood' from the internal virus called Vlove, spread through the most popular Yahoo Messenger instant messaging service today. Virus sends IM to the entire list frien
The Vietnamese Internet community is witnessing a new "flood" from the internal virus called Vlove , spread through the most popular Yahoo Messenger instant messaging service today. The virus sends an IM to the entire friends list, which the owner doesn't know about.
When receiving this message, the user absolutely does not click on the link, please ignore. In case of infection with this virus, follow these steps:
1. Download the necessary tools:
- Download Hijackthis software to manage programs started with Windows.
- Load Killbox software to delete files that windows does not allow.
2. Back up the registry
Because the following removal method is mainly related to the Registry and Hijackthis is one of the software that strongly affects this function, you need to back up (save) before attempting to prevent the problem later. Back up the registry by:
- From Start -> Run -> type regedit command -> File (in the Registry Editor window) -> Explorer -> save the exported file as you like.
- When something goes wrong with the Registry , you just need to re-enter ( Import ) the original file is ok.
3. Run Hijackthis:
Figure 1
Click " Do a system scan and save a logfile " ( Figure 1 )
Figure 2
The areas that are highlighted in red ( Figure 2 ) are the viruses created by the virus. Please check all the keys then check the checked to remove them. ( Figure 3 ).
You find and click on the following keys:
R1-HKCUSoftwareMicrosoftInternet ExlplorerMain, Default_Page_URL = http://fun.nguoiiu.com/life/
R1 - HKCUSoftwareMicrosoftInternet ExlplorerMain, SearchPage = http://fun.nguoiiu.com/life/
R0 - HKCUSoftwareMicrosoftInternet ExlplorerMain, Start Page = http://fun.nguoiiu.com/life/
R1 - HKCUSoftwareMicrosoftInternet ExlplorerMain, First Home Page = http://fun.nguoiiu.com/life/
R1 - HKCUSoftwareMicrosoftInternet ExlplorerMain, Window Title = Power by MTVC
O4 - HKCU.Run: (System32) C: WindowsSystem32.exe
O4 - HKCU.RunOnce: (Windows) C: (Windows System32victory.jse
O11 - Options Group: (International) International *
Figure 3
4. Delete files using Killbox:
You need to delete the following files:
C: WINDOWSsystem32.exe ( Figure 4 )
C: WINDOWSsystem32victory.jse
Figure 4
You should read it
- Learn about the Windows Registry - Part I
- 36 best free registry cleaning software 2018
- What is Registry Hive?
- 50 Registry tricks to help you become a true Windows 7 / Vista 'hacker' (Part 1)
- Block access to Registry Editor on Windows 10/8/7
- How to Get Into a Computer Registry
- Use the .reg file to configure the Registry in WinXP
- How to re-enable Registry backup on Windows 10
- How to Make and Restore a Backup of the Windows Registry
- How to use Wise Registry Cleaner to clean and fix registry errors
- How to fix a corrupted Registry on Windows 10
- How to create a hacked Windows Registry file yourself
Maybe you are interested
How to use ncdu to check disk space in Ubuntu Edit music file information, add Album ... with Mp3Tag How to create invisible folders on Windows 10 desktop The COUNTIFS function, how to use the cell count function according to multiple events in Excel What causes the files to be corrupt, corrupted? Things to know about IPv6 protocol