Remove ILOVEYOU virus
5 posters
Page 1 of 1
Remove ILOVEYOU virus
b]Recover from the ILOVEYOU (VBS/Loveletter) Virus[/b]
The VBS/Loveletter (aka ILOVEYOU or LoveBug) virus is quite destructive because it adds files, changes Windows registry entries, deletes some files and makes others hidden.
Stop the Virus
Press Ctrl+Alt+Del to invoke the Close Program dialog or Task Manager, depending on your operating system. Select any instance of Wscript.exe that is running, and choose End Task to kill it. Do the same with WINS-BUGFIX.exe and WinFat32.exe.
Delete Messages and Files
In Outlook, use Tools > Advanced Find to locate any items with one of these subjects and a file attachment. Delete them:
*ILOVEYOU
*Susitikim shi vakara kavos puodukui
*fwd: Joke
*Mothers Day Order Confirmation
*Dangerous Virus Warning
*Virus ALERT!!!
*Important ! Read carefully !!
*How to protect yourself from the IL0VEY0U bug!
Delete the following files, adjusting the paths as needed to match your system. Start > Find is probably the best way to locate all of these:
*C:\Temp\LOVE-LETTER-FOR-YOU.TXT.vbs
*C:\Temp\LOVE-LETTER-FOR-YOU.TXT1.vbs
*\WIN32DLL.vbs
*\\LOVE-LETTER-FOR-YOU.TXT.vbs
*\\MSKERNEL32.vbs
*Any instances of WINS-BUGFIX.exe anywhere on the system
*Any instances of Very Funny.vbs
*Any instances of Mothersday.vbs
*Any instances of virus_warning.jpg.vbs
*Any instances of protect.vbs
*Any instances of IMPORTANT.TXT.vbs
*Virus-Protection-Instructions.vbs
Delete or examine all VBS and VBE files on your system. The virus will have overwritten these types of files with copies of itself.
The virus also deletes JS, JSE, CSS, WSH, SCT, HTA, JPG, and JPEG files. It then saves another copy of the payload virus script using the original file's name, with the VBS extension added, e.g. image.jpg.vbs. The files will all have the same size and the date and time that the virus ran. You should delete these files as well.
If you use Internet Relay Chat, look for a file named Script.ini. If it contains a reference to LOVE-LETTER-FOR-YOU.HTM, you'll need to delete it or replace it with your original Script.ini, if you have a backup.
Fix Windows Registry
Remember to back up the Registry before making any changes!
Remove the following Windows Registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKERNEL32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\WIN32DLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BUGSFIX
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WinFAT32
In the HKEY_CURRENT_USER\Software\Microsoft\WAB\ key, remove all the individual STRING and DWORD entries, but not the (default) entry or any subkeys.
Rename the value of the following registry entry to your desired Internet Explorer home page:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
You may need to restore these registry entries to HKEY_CURRENT_USER, HKEY_USERS and
HKEY_LOCAL_MACHINE. A system policy file that loads at network logon should take care of that automatically:
Software\Microsoft\Windows\CurrentVersion\Policies\Network\HideSharePwds
Software\Microsoft\Windows\CurrentVersion\Policies\Network\DisablePwdCaching
.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Network\HideSharePwds
.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Network\DisablePwdCaching
The VBS/Loveletter (aka ILOVEYOU or LoveBug) virus is quite destructive because it adds files, changes Windows registry entries, deletes some files and makes others hidden.
Stop the Virus
Press Ctrl+Alt+Del to invoke the Close Program dialog or Task Manager, depending on your operating system. Select any instance of Wscript.exe that is running, and choose End Task to kill it. Do the same with WINS-BUGFIX.exe and WinFat32.exe.
Delete Messages and Files
In Outlook, use Tools > Advanced Find to locate any items with one of these subjects and a file attachment. Delete them:
*ILOVEYOU
*Susitikim shi vakara kavos puodukui
*fwd: Joke
*Mothers Day Order Confirmation
*Dangerous Virus Warning
*Virus ALERT!!!
*Important ! Read carefully !!
*How to protect yourself from the IL0VEY0U bug!
Delete the following files, adjusting the paths as needed to match your system. Start > Find is probably the best way to locate all of these:
*C:\Temp\LOVE-LETTER-FOR-YOU.TXT.vbs
*C:\Temp\LOVE-LETTER-FOR-YOU.TXT1.vbs
*\WIN32DLL.vbs
*\\LOVE-LETTER-FOR-YOU.TXT.vbs
*\\MSKERNEL32.vbs
*Any instances of WINS-BUGFIX.exe anywhere on the system
*Any instances of Very Funny.vbs
*Any instances of Mothersday.vbs
*Any instances of virus_warning.jpg.vbs
*Any instances of protect.vbs
*Any instances of IMPORTANT.TXT.vbs
*Virus-Protection-Instructions.vbs
Delete or examine all VBS and VBE files on your system. The virus will have overwritten these types of files with copies of itself.
The virus also deletes JS, JSE, CSS, WSH, SCT, HTA, JPG, and JPEG files. It then saves another copy of the payload virus script using the original file's name, with the VBS extension added, e.g. image.jpg.vbs. The files will all have the same size and the date and time that the virus ran. You should delete these files as well.
If you use Internet Relay Chat, look for a file named Script.ini. If it contains a reference to LOVE-LETTER-FOR-YOU.HTM, you'll need to delete it or replace it with your original Script.ini, if you have a backup.
Fix Windows Registry
Remember to back up the Registry before making any changes!
Remove the following Windows Registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKERNEL32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\WIN32DLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BUGSFIX
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WinFAT32
In the HKEY_CURRENT_USER\Software\Microsoft\WAB\ key, remove all the individual STRING and DWORD entries, but not the (default) entry or any subkeys.
Rename the value of the following registry entry to your desired Internet Explorer home page:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
You may need to restore these registry entries to HKEY_CURRENT_USER, HKEY_USERS and
HKEY_LOCAL_MACHINE. A system policy file that loads at network logon should take care of that automatically:
Software\Microsoft\Windows\CurrentVersion\Policies\Network\HideSharePwds
Software\Microsoft\Windows\CurrentVersion\Policies\Network\DisablePwdCaching
.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Network\HideSharePwds
.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Network\DisablePwdCaching
Re: Remove ILOVEYOU virus
wow. grade vinay bro. it's very helpfully for our computers. thanks bro. excellant tricks
Re: Remove ILOVEYOU virus
thx to informing vinay ... will deff chck for it ...
luv.inspecta- Legendary Member
-
Number of posts : 1642
Age : 38
Location : saudi arabia
mig33 username : luv.inspecta
Registration date : 2008-05-19
Re: Remove ILOVEYOU virus
i love you virus
i thought it could be a joke...thats why clicked on the topic
i thought it could be a joke...thats why clicked on the topic
Guest- Guest
Re: Remove ILOVEYOU virus
realy gud to have computer wizards in the community...
very benefitial
very benefitial
r0mz- Senior member
-
Number of posts : 935
Age : 39
Location : Tanzania
mig33 username : r0mz---relo4d3d
Registration date : 2008-06-10
Re: Remove ILOVEYOU virus
hahaha nice trick to kick i love you ( virus )
getmywishes- Valued Member
-
Number of posts : 386
Age : 44
Location : in your wishes
mig33 username : getmywishes
Referrer : miss_jaguar
Registration date : 2008-08-30
Similar topics
» Remove DOS.
» remove microsoft msn messenger who are using old xp
» REMOVE RECYCLE BIN FROM UR DESK TOP!!!!
» Remove kick menu & save MIG33
» while your away (virus)
» remove microsoft msn messenger who are using old xp
» REMOVE RECYCLE BIN FROM UR DESK TOP!!!!
» Remove kick menu & save MIG33
» while your away (virus)
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum