Love$ Virus

The encrypted files may not be the only damage done to you. parasite may still be hiding on your PC. To determine whether you've been infected with ransomware, we recommend downloading SpyHunter.

Download SpyHunter Anti-Malware

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.


Love$ is a malicious program from the ransomware category that is used to prevent users from accessing their own digital files. As most ransomware infections, Love$ applies encryption to the targeted files and then demands a ransom from the owners.


The Love$ virus will encrypt your files and leave a message in a FILES ENCRYPTED.txt file.

The ransomware threats are very popular tools for money extortion that the cybercriminal use more and more to make quick money through a simple blackmail scheme. These threats are also very efficient in remaining undetected when secretly applying encryption to the victim’s files. They normally show no visible symptoms of their activity and can remain under the radar of most antivirus programs which gives them the advantage of surprise.

Love$, in particular, is an advanced ransomware cryptovirus that applies a complex encryption code to the files it detects on the infected computer and demands money from the victims in order to undo what it has done. The hackers who control this infection typically place a ransom notification with instructions on how to transfer the money and promise that, as soon as they receive the payment, they will send a decryption key that can unlock the files that Love$ has encrypted.

However, it is unwise to trust promises made by the same individuals who are liable for compromising your computer and encrypting your own data. After all, Love$’s hackers are only after your money, and once you send it to them, they can’t care less whether you can recover your files or not. That’s why it is perfectly possible that they will never send you a decryption key when they receive the ransom payment.

The Love$ virus

The Love$ virus is a ransomware threat that targets digital records and attempts to restrict the owners from access to them. Once the Love$ virus encrypts the files on the infected machine, it displays a notification that demands a ransom for a decryption key.

For those who don’t keep very important files on their computers (or keep external backups) the attack of Love$ may not be that catastrophic because they have a way to access their files without paying a ransom. Besides, the ransomware virus normally doesn’t cause any other problems in the system and is not expected to steal confidential data or spy on its victims like a Trojan or Spyware. All it does is it encrypts user files and asks a ransom for them but once it is removed, the system can work normally and the files can be restored from backups.

The problem comes when there are no backup copies and the files that are encrypted are of great importance. In this situation, the victims really need to consider all the available alternatives to deal with the ransomware in the best possible way.

The Love$ file decryption

The Love$ file decryption is a file-recovery method that can make the files that Love$ encrypted available again. The decryption of the Love$ files, however, requires a special key for decryption which is unique for each infected computer and is kept in secret by anonymous cybercriminals.

It may initially seem that the easiest way to deal with the infection is to pay the demanded ransom and receive a decryption key from the hackers behind Love$ but, sadly, there is a high chance of losing your money in vain if you go this way. That’s why we suggest you to first check our guide on how to remove the virus and explore some alternatives that may help you restore some of your most needed files for free. If nothing works, you may even want to consider contacting a professional instead of giving your money to anonymous cybercrooks.



Name Love$
Type Ransomware
Danger Level High (Ransomware is by far the worst threat you can encounter)
Symptoms Very few and unnoticeable ones before the ransom notification comes up.
Distribution Method From fake ads and fake system requests to spam emails and contagious web pages.
Data Recovery Tool Currently Unavailable
Detection Tool

Remove Love$ Ransomware


Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).



We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. We recommend downloading SpyHunter to see if it can detect parasite for you.

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab. Try to determine which processes are dangerous.


Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at:

Scan Results

Virus Scanner Result

After you open their folder, end the processes that are infected, then delete their folders.

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections.


Hold the Start Key and R copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Type msconfig in the search field and hit enter. A window will pop-up:


Go in Startup —> Uncheck entries that have “Unknown” as Manufacturer.

  • Please note that ransomware may even include a fake Manufacturer name to its process. Make sure you check out every process here is legitimate.


To remove parasite on your own, you may have to meddle with system files and registries. If you were to do this, you need to be extremely careful, because you may damage your system.

If you want to avoid the risk, we recommend downloading SpyHunter
a professional malware removal tool.

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

Type Regedit in the windows search field and press Enter. Once inside, press CTRL and F together and type the virus’s Name.

Search for the ransomware in your registries and delete the entries. Be extremely careful – you can damage your system if you delete entries not related to the ransomware.

Type each of the following in the Windows Search Field:

  1. %AppData%
  2. %LocalAppData%
  3. %ProgramData%
  4. %WinDir%
  5. %Temp%

Delete everything in Temp. The rest just check out for anything recently added. Remember to leave us a comment if you run into any trouble!


How to Decrypt Love$ files

We have a comprehensive (and daily updated) guide on how to decrypt your files. Check it out here.

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Leave a Comment