Shortcut virus is a Trojan and Worm in one. It replicates files and hides data on infected storage devices. USB flash drive is known to be the easy target of this virus. However, HDD (hard disk drive) and even (Solid-state drive) SSD’s are also susceptible.
Advertisements
- How Shortcut Virus Infects Computer?
- How effective is antivirus against it?
- Types of Shortcut virus
- What to do when your Flash drive got infected by shortcut virus?
- Method 1: remove shortcut virus using Trojorm Remover Tool
- Method 2: remove shortcut virus using registry
- Fix-folder access denied error
- How TO remove stubborn shortcut virus from extremely infected PC or Flash Drive
- How to prevent shortcut virus from coming back?
- Trojan virus is known to be tricky. One of its characteristics is hiding the real file and pose a fake one, which is an executable file that carries a virus.
- Worm, on the other hand, is a malware that keeps on duplicating itself. Sounds great, the Trojan hides the data, front the Worm as the real one and once executed, you know what will happen next.
How Shortcut Virus Infects Computer?
A simple insertion of infected flash drive into your PC will get your computer infected, immediately and vice versa.
How effective is antivirus against it?
Unfortunately, not all antivirus can detect and remove shortcut virus. But there are handful can do, to mention a few, trojorm removal tool, smadav, and usbfix.
Are you worried? I have good news for you! In less than a minute, you can easily remove, terminate, and prevent shortcut virus from your computer by yourself. YES! All you need is to follow the step by step guide below.
Advertisements
Types of Shortcut virus
- Emsisoft – Trojan.VBS.TTE (B), Trojan.Generic.7206697 (B).
- ESET – VBS/Autorun.EY worm, Win32/Ramnit.A virus.
- Microsoft Security Essential – Worm:VBS/Cantix.A.
- McAfee – VBS/Autorun.worm.k virus.
- AVG – VBS/Worm.BH.
- Bitdefender – Trojan.VBS.TTE.
- ClamWin – VBS.Agent-35.
- Quickheal – VBS/Canteix.AK.
- Sophos – Troj/Agent-NXIMal/FakeAV-BW, Mal/Bundpil-LNK.
- ClamAV – W32.Trojan.Starter-2, W32.Exploit.CVE-2010_2568-1.
- Avira – W32/Sality.AB.2
- SmadAV – VBS.Serviks, Serviks.Shortcut, Ramnit.CPL and Bundpil.Shortcut.
- Norton – Trojan.Gen.2 (Shortcut virus)
Tips: For most of the time this virus ends with .EXE, .VBS. LNK and .INI file extensions.
Files and folder shortcut.vbs and .lnk will look like just your ordinary files such as; word processor, presentation, folder, audio, and video files.
Flash Drive shortcut.ini and .exe makes an imitation of your flash drive consolidates your real data into one folder and hide it.
Advertisements
What to do when your Flash drive got infected by shortcut virus?
The best thing you can do is to make-it-a-habit, not to open your portable devices or hard drive via autorun or on “My computer”. See the below lists:
- Do not open your Flash Drive via autorun and on My Computer.
- Open your Flash Drive and Hard Disk by right-clicking it, then click explore or type its drive letter in the windows address bar to prevent any script from running.
- Follow this, how to unhide files and folder hidden by the virus. To unhide your hidden data and avoid executing it.
Method 1: remove shortcut virus using Trojorm Remover Tool
1 You need to download the trojorm remover tool and Fix folder. Once downloaded, extract it using WinRAR or any other file decompressor.
2 Then, make sure that you run trojorm remover tool inside your flash drive, wait until the scan is complete and press enter.
3 Next, copy and paste the fix-folder.vbs (this is a good .vbs file) inside your flash drive, HDD, SSD, and external drive. Right-click it, choose open with and select notepad. Look for the cDrive = “H:”, change it according to your drive letter (ex. E, F, G and so on). Then exit notepad and save.
5 You must see a dialog box confirming that everything is fixed.
Method 2: remove shortcut virus using registry
Please take note that this guide is for advanced users only. I will not be held liable for whatever consequences that may take place after following this guide. I am not trying to frighten you but one mistake may affect your PC’s normal operation.
1 Press the windows key + R, type “regedit” to enter the registry.
2 Navigate through hkey_current_user / Software / Microsoft / Windows / CurrentVersion / Run. Normally, you shouldn’t see any key except the default as you can see in the image below. Any key that is unusual such as
3 Press the Windows key + R again, type “MSConfig” click “OK“, in “Startup” tab uncheck everything except your antivirus. Click “OK” and “Restart now”.
Fix-folder access denied error
Solutions:
Open fixfolder with notepad, see to it that you change the drive according to your Flash drive and hard disk drive letter.
What if you did everything right, from changing drive letter and typing the attrib command accurately as it is and still receive the access denied error?
Run CHKDSK command using CMD. If you don’t know how to do it? Please visit this guide Windows detected a hard disk problem.
How TO remove stubborn shortcut virus from extremely infected PC or Flash Drive
You followed the virus remover guide above and found it helpful. In fact, your shortcut-virus problem is now solved. However, after plugging again your Flash drive, external hard drive (HDD) and SD card it became infected again. Why this happen?
1 Download RogueKiller and run it as well. To remove any variants of trojans.
2 Download Malwarebytes , install, update and run a scan. For more malware removal that RogueKiller might miss.
3 Install SmadAV Antivirus. A finishing touch, this also removes Bundpil.Shortcut-virus and act as computer shield against it. Thus, preventing future infections.
Note: Please do not restart your PC until you finished installing SmadAV antivirus.
How to prevent shortcut virus from coming back?
Install SmadAV as your primary defence and a good antivirus. Then do a weekly scan with Malwarebytes, for better protection. Do not let anyone insert portable devices into your computer unless it is virus scanned and found safe to use.
Your comments and suggestions are highly appreciated to improve this How to Remove Tutorial. Speak up your mind in the comment box below.
ramil says
May 25, 2017 at 7:15 am
Will this work with the drive.bat virus? thank you.
I.C Tiempo says
Yes it will.
sera says
Really thank you.I have removed Shortcut Virus. very useful.
I.C Tiempo says
Hi, thank you for such a kind comment. Am glad that you found this shortcut virus remover guide useful.
Vanessa says
hi! i’ve done everything until changing letter f in the notepad to my disk letter which is E. Yet when I try to open the fix folder via command prompt (because first method didn’t work/access denied), it will appear only for a while (like for one second) then it will automatically close. I cannot continue with the rest of the instructions because of this. can you please help me asap? thanks!
I.C Tiempo says
Hi Vanessa, Please install and run SmadAV antivirus, scan your flash drive and hard drive partition. Then after which, run the fixfolder.
YAZAAN says
How can I remove new folder virus?
I.C Tiempo says
Have you tried all the steps above? If it has the same characteristic as shortcut virus that hides your original file and makes a new folder or file with .exe extension. Then, following the guides above are beneficial.
Mich says
I have a question. I’m kinda new to this whole shortcut virus thing since I’m not tech savvy. But I just found out my usb is infected and no matter what I do, the short cut thing keeps happening each time I plug it on the laptop. I’m currently getting my laptop scanned and followed your steps. Thanks btw. But I was wondering. The virus seems to affect only one usb. And so I’m worried now if my other external devices are infected since I use them in one computer. They don’t seem to be. Is there a way to scan or find out? Thanks again.
I.C Tiempo says
Hi Mich, the common symptoms of shortcut virus infected device is, it has a lot of shortcut files. If your other device don’t have such, it’s clean.
Nick Twisted says
Method nr.1. (Trojorm remover + Fixfolder). Very easy to follow. Thanks.