My Lucky 123 “Virus” Removal (Chrome/Firefox)

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

This page aims to help you remove “My Lucky 123”. These “My Lucky 123” removal instructions work for Chrome, Firefox and Internet Explorer, as well as every version of Windows.

There are some specific programs known as Browser hijackers that, once inside a PC, usually mess with the user’s browsers in a very intrusive way. For example, they may impose some undesired changes to your Firefox or Chrome browser, replace your homepage with an unknown one, insert a search engine that may redirect your searches to pages with aggressive ads, pop-ups, and banners and constantly interrupt your normal browsing with unnecessary messages. You are probably on this page because you are facing a disturbance of this type, caused by a program called “My Lucky 123”. The chance is that you are heavily irritated by this browser hijacker and you are looking for ways to remove it. Fortunately, we have an effective solution for you that will help you manually uninstall “My Lucky 123” from your PC and bring your browser back to normal. Below you will find a removal guide with all the instructions you may need to successfully get rid of this program and all of its traces. We have given you also a useful description of this software and the way it operates. Knowing more about it will surely help you remove the unwanted program effectively and prevent close interactions with this type of programs in the future.

My Lucky 123 "Virus"

My Lucky 123 in Chrome

What is My Lucky 123 “Virus”?

First of all let’s clear that confusion up. “My Lucky 123” is not an actual virus. According to security experts, “My Lucky 123” is a potentially unwanted program (PUP) from the category of browser hijackers. When in your system, this software usually takes over your default browser, imposes its changes to your homepage and search engine and installs some plug-ins and add-ons deep inside your system. This is usually done in order to ensure that you are exposed to as many advertisements as possible and most of your searches get redirected to various promotional web pages. The reason for this rather aggressive invasion is that this program is involved in a remuneration model known as Pay-Per-Click. Every time you click on the websites, ads, pop-ups and banners this browser hijacker displays on your screen, its owners earn revenue from your clicks. This is a marketing strategy that helps many online vendors display their ads directly on the user’s monitor and enables other businesses to profit from the paid ads. However, despite there being nothing wrong with this strategy, some users may suffer from a heavy browsing-related disturbance caused by the browser hijacker’s intrusiveness. This is the main reason why they often seek ways to remove it from their computers and bring their browser settings back to normal.

“My Lucky 123” – what to do?

Many people, who are facing “My Lucky 123” and all its obtrusive popping windows, may think that there is something wrong with their PC. The excessive amount of advertisements and the constant page redirects may not only cause interruption to their browsing but it may even cause their computer to operate in a sluggish manner. Moreover, their attempts to restore their old settings are usually in vain because bringing the browser settings back is not possible unless they fully uninstall “My Lucky 123” from their computers. This is something very upsetting and some inexperienced users may consider the browser hijacker to be an alarming threat or a virus.

The good thing is that these programs are not as malicious as a Trojan horse infection or Ransomware. In fact, they are pretty harmless and do not contain scripts that can corrupt your system. Real malware from the rank of Ransomware will cause serious damage to your data and blackmail you, while the worst a program like “My Lucky 123” could do is redirect you to different web pages and nagging ads. However, even if there is no direct risk that browser hijackers could expose you to, for your own safety we would advise you to avoid interacting with the randomly generated messages that pop up out of nowhere. You never know when you may come across suspicious commercial websites infected with viruses and various harmful threats.

How to prevent browser hijackers from getting inside your system?

We always advise our users to pay attention when interacting with online content and especially when downloading and installing software on their machines. Potentially unwanted programs like “My Lucky 123” are usually distributed through software bundles. That’s why it is really important to always check the installation packages of the programs you are about to install for such added software. The quickest way to do this is through the advanced/custom option in the setup, where you can manually deselect them. It is a good idea to avoid the standard installation option and always opt for more detailed settings because this gives you more control over the programs you will install on your computer and will help you keep it bloatware free.


Name “My Lucky 123”
Type  Browser Hijacker
Danger Level Medium (nowhere near threats like Ransomware, but still a security risk)
Symptoms Your homepage is replaced, your search engine redirects you to different pages and your screen is injected with ads and pop-ups.
Distribution Method Usually bundled inside software installers, but could be found also in spam emails, direct downloads, freeware platforms, torrent platforms.
Detection Tool

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you’ll need to purchase the full version.
More information about SpyHunter and steps to uninstall.


My Lucky 123 “Virus” Removal (Chrome/Firefox)



Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).


To remove parasite, you may have to meddle with system files and registries. Making a mistake and deleting the wrong thing may damage your system.
Avoid this by using SpyHunter - a professional Parasite removal tool.

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Reveal All Hidden Files and Folders.

  • Do not skip this  – “My Lucky 123” may have hidden some of its files.

Hold together the Start Key and R. Type appwiz.cpl –> OK.


You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

Type msconfig in the search field and hit enter. A window will pop-up:


Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.


Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

  1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click  Properties.
  2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
  3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.



Right click on the browser’s shortcut —> Properties.

NOTE: We are showing Google Chrome, but you can do this for Firefox and IE (or Edge).


Properties —–> Shortcut. In Target, remove everything after .exe.

ie9-10_512x512  Remove “My Lucky 123” from Internet Explorer:

Open IE, click  IE GEAR —–> Manage Add-ons.

pic 3

Find the threat —> Disable. Go to IE GEAR —–> Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

firefox-512 Remove “My Lucky 123” from Firefox:

Open Firefoxclick  mozilla menu  ——-> Add-ons —-> Extensions.

pic 6

Find the adware/malware —> Remove.
chrome-logo-transparent-backgroundRemove “My Lucky 123” from Chrome:

Close Chrome. Navigate to:

 C:/Users/!!!!USER NAME!!!!/AppData/Local/Google/Chrome/User Data. There is a Folder called “Default” inside:

Rename the Folder to Backup Default

Rename it to Backup Default. Restart Chrome.

  • At this point the threat is gone from Chrome, but complete the entire guide or it may reappear on a system reboot.


Press CTRL + SHIFT + ESC simultaneously. Go to the Processes Tab. Try to determine which ones are dangerous. Google them or ask us in the comments.


This is the most important and difficult part. If you delete the wrong file, it may damage your system irreversibly. If you can not do this,
>> Download SpyHunter - a professional parasite scanner and remover.

Keep in mind, SpyHunter’s malware detection tool is free. To remove the infection, you'll need to purchase its full version. More information about SpyHunter and steps to uninstall.

Right click on each of the problematic processes separately and select Open File LocationEnd the process after you open the folder, then delete the directories you were sent to.



Type Regedit in the windows search field and press Enter.

Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show this way, go manually to these directories and delete/uninstall them:

  • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
    HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
    HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random

Remember to leave us a comment if you run into any trouble!

  • Tasmeen Taj # fix for traceroute and netstat display anomaly

    • HowToRemove.Guide Team

      Hi Tasmeen,
      you should delete these IPs .

  • Sourabrata

    I’ve tried doing everything, but the mylucky123 page still loads up everytime I open one of the browsers installed on my computer.

    • HowToRemove.Guide Team

      Hi Sourabrata,
      did you manage complete all the steps in Safe Mode?

  • Ashwin

    # uncheckit_begin
    # These rules were added by the Uncheckitprogram in order to block advertising software modules # fix for traceroute and netstat display anomaly
    After local host the following are there,
    # uncheckit_end

    • HowToRemove.Guide Team

      Hi Ashwin, you have Uncheckit installed, which is blocking these domains from displaying adverts on your PC. That is a good thing.

  • x

    How can you actually determine which files are dangerous???

    • HowToRemove.Guide Team

      Hi there, it’s mostly trial and error. You can upload suspicious files to the virus total site to check them.

  • fitri

    # unchecky_begin
    # These rules were added by the Unchecky program in order to block advertising software modules # fix for traceroute and netstat display anomaly
    # unchecky_end

    • HowToRemove.Guide Team

      Hi there, you have unchecky installed, which blocks these sites from showing ads on your PC. That is a good thing. Are those all the entries in the hosts file?

  • HowToRemove.Guide Team

    Hi Dimas, try Searching for notepad first. Type notepad in the search bar, right click on it and select Run as Admin. Now open Notepad, click on File-> Open and manually navigate to the file. It’s in C://Windows/System32/drivers/etc/

  • HowToRemove.Guide Team

    Glad it worked for you 🙂

  • Raikuro Sama

    Hi, when I try the “notepad%windir%/system32/Drivers/etc/hosts”, i get this underneath local hosts… is that ok?

    • HowToRemove.Guide Team

      Hello Raikuro, means you PC won’t be able to access the mcafee update site. This means that either a malware has blocked the program from updating or you are using a pirated copy of the program. Either way i recommend you delete the line.

  • Arun

    I have the suspicious IP in the hosts file

    • HowToRemove.Guide Team

      Hi Arun,
      can you post us your IPs so we can check them? Or you can make us a screenshot.

  • HowToRemove.Guide Team

    Hi Aradhana,
    you should delete these IPs.

  • HowToRemove.Guide Team

    Hi Jaap van den Berg,
    the IPs you are looking for are in the hosts.txt file. There you can easily remove these entries.

    • Jaap van den Berg

      I have removed them from the file but the system does not allow me to save the file and overwrite it even though I am logged in as admin…
      Never mind. I changed the access permissions for this file and now it has been overwritten 🙂

      • HowToRemove.Guide Team

        Great. Have you noticed anything suspicious in your system after that?

  • HowToRemove.Guide Team

    Hi Dayennyk,
    i would suggest to you yo delete these IPs.

  • Richard Stewart

    i cant delete the ips because i dont have permission even though i am admin and have enabled permissions under security thislineskipsanyemptylines
    ok i sorted it out thanks

    • HowToRemove.Guide Team

      Hi Richard,
      yes you should delete these IPs.

      • Richard Stewart

        Thnx I have removed them

        • HowToRemove.Guide Team

          You are welcome Richard 🙂