How to Remove TAGA LIPA ARE! Virus
If you're new here, you may want to subscribe to Windows Reference RSS feed Thanks for visiting!
First thing is to get familiar with the ‘virus’. The ‘virus’ file is FS6519.dll.vbs. It’s a VB Script that does nothing except make a copy of itself in all your drives and change the title of Internet Explorer to “TAGA LIPA ARE!”.
First, configure your folders to show system, OS and hidden files and file extensions. Remove/Delete
C:\Windows\FS6519.dll.vbs
I would suggest using the Shift + Del here.
Second, open
regedit
in the run command. Remove the registry entry
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/Current Version/Run/FS6519.dll
Then Remove all copies of the file
FS6519.dll.vbs
and
autorun.ini
from all your drives. Again, I suggest using Shift + Del here.
To restore the name of IE to Internet Explorer, change the value of
HKEY_CURRENT_USER/Software/Microsoft/Internet Explorer/Main/Window Title
from “TAGA LIPA ARE!” to “Internet Explorer” by double clicking the registry entry. And that’s it, the ‘virus’ is gone.(Tip : You can also put your desired name here like your name)
It’s really harmless and if you ask me, it looks something that an attention-seeking-twelve-year-old-with-a-compiler would do. And you, on the other hand, should know better next time.
Random Posts
Did you enjoy this post? Why not leave a comment below and continue the conversation, or subscribe to my feed and get articles like this delivered automatically each day to your feed reader.
Trackbacks & Pingbacks
Comments
Leave a comment
Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>






Use Combofix to remove the abouve,it will remove all perfect solution