Categories
how to tutorials tips & tricks windows hacks xp hacks

How to Remove Hacked by godzilla virus in 5 minutes

Now a days with the increasing use of portable drives various types of virus infect a large number of system very easily.

One of these common virus is "Hacked by Godzilla Virus" which normally spreads through portable drives etc.

My system got infected with this Hacked by Godzilla Virus and I repaired my system without the help of any antivirus software.

Lets first discuss the common symptoms of the Godzilla Virus.

If your system is infected by this virus you will see the this text "Hacked by Godzilla Virus" in the title at the top of the window of Internet explorer

Some other symptoms:

1. Task manager is disabled.

2. Regedit (Command for registry edit) is disabled.

3. Folder options got disappeared From windows explorer.

4. Double clicking on any of your system drive( c: ,d: etc) initiates a new instance of the virus.

So, you won’t be able to open any of your drive by double click rather you have to open then by right click >> explore.

5. msconfig command is disabled – this virus is not dependent on system startup but it disables the msconfig command used to modify the system startup programs.

Let’s see how you can remove Godzilla virus in 5 minutes.

Follow the Step by step procedure given below to remove hacked by godzilla virus.


1. First download process explorer ,run it and end all the process which are running as wscript.exe

2. Download RRT.exe (Remove restrictions tool)

You may be wondering..what is RRT?

So for your FYI: RRT (Remove Restrictions Tool) v.1.0 is a tiny tool that does the work for AVs, it re-Enables all what the virus had disabled, and brings every thing including task manager ,regedit ,msconfig and hidden folder options back.

3. now, you have regedit command enabled.

Browse to Go to HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run and delete MS32DLL (right click on it and select delete)

Go to HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main and delete “Window Title” which has it’s value of “Hacked by Godzilla“ or you can also write your name as a recognition for yourself.

4. Open My Computer,File menu go to Tools -> Folder Options, click on View tab

Under Advance settings,
check “Show Hidden files and folders“,
uncheck “Hide extensions for known file types“,
uncheck “Hide protected operating system files (Recommended)
and click “OK” button

5. now right click on each of your drive and click explore now delete the files with names autorun.inf and MS32DLL.dll.vbs including your USB Drive

6. Restart your PC and your PC should be clean from Hacked by Godzilla.

Leave your comments if you have any issues in following the above procedure.

40 replies on “How to Remove Hacked by godzilla virus in 5 minutes”

4 days ago i follwd the instructions to remove HACKED BY GODZILLA, and its goood. but the problem now in my PC is RRT v4.7.o.2-monitoring and said that r-media malware detected! and it needs urgent attention! when i open RRT window it shows the FIREWALL SHARED ACCESS
when i put a chck on it it shows that i need to restart the PC and thats what i did, after restarting it shows that my PC might be at risk the firewall is OFF so i put it ON but evrytime ill use my PC it keeps repeating, could you pls help me on this. Thanks

Hey thanks a lot buddy.. have followed your steps and succesffuly resolved this ‘hacked by godzilla’ issue.. God bless you!!!

Really Good…. Solution to remove the Effected Virus .

Thanx

With Regards
Rakesh

thnx for really a great help.
it really works.
i have successfuly removed title hacked by godzila.

thanks

irfan

Hi I already followed the instructions and I removed the “hacked by godzilla” virus from my account on my pc. But there is another account on the same pc that still has the virus, and I cant find the specific files that I have to delete because I already deleted them before, so my account can work.

@diab.91@hotmail.com – if you have followed the procedure properly there will be no virus but if you had missed anything in terms of deletion of files there virus may become active again.

Hi,

I don’t understand step 3. Where do I find this:
Browse to Go to HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run and delete MS32DLL (right click on it and select delete)

Go to HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main and delete “Window Title” which has it’s value of “Hacked by Godzilla“ or you can also write your name as a recognition for yourself.

when I try to use IE it says hacked by godzilla.
Can you help me. There was a lot of hard work in building my website. I dont want it gg down. Help please thanks.

@Jess – In step 3, you need to open open registry by pressing window+ r and navigate to.

HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run and delete MS32DLL

now navigate to the following path

HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main

and change the value in windows title or delete it….and follow the steps further

@Yohan Perera – Some anti virus reports unsigned programs as virus…but rrt is not a virus. You can read the policy from rrt homepage

5. now right click on each of your drive and click explore now delete the files with names autorun.inf and MS32DLL.dll.vbs including your USB Drive

i can not find MS32DLL.dll.vbs and therefore i cant delete it

there are al lot of files named autorun.inf because of games, which one am i to delete

help please im only seconds away from getting rid of this mess 😀

Hello,
I am certain that I have this virus but I cannot find the files at the specified path in step 3:
Browse to Go to HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run and delete MS32DLL (right click on it and select delete)

Go to HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main and delete “Window Title” which has it’s value of “Hacked by Godzilla“ or you can also write your name as a recognition for yourself.

I also cannot find any files by the names listed in step 5. now right click on each of your drive and click explore now delete the files with names autorun.inf and MS32DLL.dll.vbs including your USB Drive

Please help. thanks

wow. that was really useful. i didn’t have the godzilla virus but it emulated those exact symptoms. 😀 thanks a lot!

I cant delete MS32DLL.dll.vbs it says u cant delete it and i’ve closed al applications but it’s not working

how are you today?
now this virus “hacked by godzilla”, i came accross a similar virus that states “hacked by sam”. the procedure that is here by given for cleaning the “hacked by godzilla virus”can also be used for cleaning the latter.

First thanks, this method has been a gem for me twice now! (Any tips on PREVENTING this virus from re-attacking?!)
Secondly, for those who stumbled at step 3. I also tripped up here and would suggest double checking the two parts of the step. First you are deleting MS32DLL from
HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run
and then you are removing the ‘Hacked by Godzilla’ title in
HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main

Be sure you are in
‘HKEY_LOCAL_MACHINE’ for the first part and
‘HKEY_CURRENT_USER’ for the second.

=) Good luck

Hi,

Thanx a lot worked for me too, i think …

I didn’t pay attention here though, thanx for pointing that out!

“Be sure you are in
‘HKEY_LOCAL_MACHINE’ for the first part and
‘HKEY_CURRENT_USER’ for the second.@

Hello,

I have followed the steps succesfully untill I faced step 5.
When I checked ‘show hidden files and folders’ there were none by the name of autorun.inf and MS32DLL.dll.vbs.
Is this a problem? ‘Hacked by Godzilla’ is gone, but is only the name gone or has the virus been deleted?

Thanks in advance!

Chiel

You forgot nummber 1 and 2:

Under Advance settings,
check “Show Hidden files and folders“,
—1—> uncheck “Hide extensions for known file types“, uncheck “Hide protected operating system files (Recommended)”<—–
and click “OK” button

Leave a Reply

Your email address will not be published. Required fields are marked *