Shortcut virus is a Trojan and Worm in one. It replicates files and hides data on infected storage devices. USB flash drive is known to be the easy target of this virus. However, HDD (hard disk drive) and even (Solid-state drive) SSD’s are also susceptible.
Advertisements
- How Shortcut Virus Infects Computer?
- How effective is antivirus against it?
- Types of Shortcut virus
- What to do when your Flash drive got infected by shortcut virus?
- Method 1: remove shortcut virus using Trojorm Remover Tool
- Method 2: remove shortcut virus using registry
- Fix-folder access denied error
- How TO remove stubborn shortcut virus from extremely infected PC or Flash Drive
- How to prevent shortcut virus from coming back?
- Trojan virus is known to be tricky. One of its characteristics is hiding the real file and pose a fake one, which is an executable file that carries a virus.
- Worm, on the other hand, is a malware that keeps on duplicating itself. Sounds great, the Trojan hides the data, front the Worm as the real one and once executed, you know what will happen next.
How Shortcut Virus Infects Computer?
A simple insertion of infected flash drive into your PC will get your computer infected, immediately and vice versa.
How effective is antivirus against it?
Unfortunately, not all antivirus can detect and remove shortcut virus. But there are handful can do, to mention a few, trojorm removal tool, smadav, and usbfix.
Are you worried? I have good news for you! In less than a minute, you can easily remove, terminate, and prevent shortcut virus from your computer by yourself. YES! All you need is to follow the step by step guide below.
Advertisements
Types of Shortcut virus
- Emsisoft – Trojan.VBS.TTE (B), Trojan.Generic.7206697 (B).
- ESET – VBS/Autorun.EY worm, Win32/Ramnit.A virus.
- Microsoft Security Essential – Worm:VBS/Cantix.A.
- McAfee – VBS/Autorun.worm.k virus.
- AVG – VBS/Worm.BH.
- Bitdefender – Trojan.VBS.TTE.
- ClamWin – VBS.Agent-35.
- Quickheal – VBS/Canteix.AK.
- Sophos – Troj/Agent-NXIMal/FakeAV-BW, Mal/Bundpil-LNK.
- ClamAV – W32.Trojan.Starter-2, W32.Exploit.CVE-2010_2568-1.
- Avira – W32/Sality.AB.2
- SmadAV – VBS.Serviks, Serviks.Shortcut, Ramnit.CPL and Bundpil.Shortcut.
- Norton – Trojan.Gen.2 (Shortcut virus)
Tips: For most of the time this virus ends with .EXE, .VBS. LNK and .INI file extensions.
Files and folder shortcut.vbs and .lnk will look like just your ordinary files such as; word processor, presentation, folder, audio, and video files.
Flash Drive shortcut.ini and .exe makes an imitation of your flash drive consolidates your real data into one folder and hide it.
Advertisements
What to do when your Flash drive got infected by shortcut virus?
The best thing you can do is to make-it-a-habit, not to open your portable devices or hard drive via autorun or on “My computer”. See the below lists:
- Do not open your Flash Drive via autorun and on My Computer.
- Open your Flash Drive and Hard Disk by right-clicking it, then click explore or type its drive letter in the windows address bar to prevent any script from running.
- Follow this, how to unhide files and folder hidden by the virus. To unhide your hidden data and avoid executing it.
Method 1: remove shortcut virus using Trojorm Remover Tool
1 You need to download the trojorm remover tool and Fix folder. Once downloaded, extract it using WinRAR or any other file decompressor.
2 Then, make sure that you run trojorm remover tool inside your flash drive, wait until the scan is complete and press enter.
3 Next, copy and paste the fix-folder.vbs (this is a good .vbs file) inside your flash drive, HDD, SSD, and external drive. Right-click it, choose open with and select notepad. Look for the cDrive = “H:”, change it according to your drive letter (ex. E, F, G and so on). Then exit notepad and save.
5 You must see a dialog box confirming that everything is fixed.
Method 2: remove shortcut virus using registry
Please take note that this guide is for advanced users only. I will not be held liable for whatever consequences that may take place after following this guide. I am not trying to frighten you but one mistake may affect your PC’s normal operation.
1 Press the windows key + R, type “regedit” to enter the registry.
2 Navigate through hkey_current_user / Software / Microsoft / Windows / CurrentVersion / Run. Normally, you shouldn’t see any key except the default as you can see in the image below. Any key that is unusual such as
3 Press the Windows key + R again, type “MSConfig” click “OK“, in “Startup” tab uncheck everything except your antivirus. Click “OK” and “Restart now”.
Fix-folder access denied error
Solutions:
Open fixfolder with notepad, see to it that you change the drive according to your Flash drive and hard disk drive letter.
What if you did everything right, from changing drive letter and typing the attrib command accurately as it is and still receive the access denied error?
Run CHKDSK command using CMD. If you don’t know how to do it? Please visit this guide Windows detected a hard disk problem.
How TO remove stubborn shortcut virus from extremely infected PC or Flash Drive
You followed the virus remover guide above and found it helpful. In fact, your shortcut-virus problem is now solved. However, after plugging again your Flash drive, external hard drive (HDD) and SD card it became infected again. Why this happen?
1 Download RogueKiller and run it as well. To remove any variants of trojans.
2 Download Malwarebytes , install, update and run a scan. For more malware removal that RogueKiller might miss.
3 Install SmadAV Antivirus. A finishing touch, this also removes Bundpil.Shortcut-virus and act as computer shield against it. Thus, preventing future infections.
Note: Please do not restart your PC until you finished installing SmadAV antivirus.
How to prevent shortcut virus from coming back?
Install SmadAV as your primary defence and a good antivirus. Then do a weekly scan with Malwarebytes, for better protection. Do not let anyone insert portable devices into your computer unless it is virus scanned and found safe to use.
Your comments and suggestions are highly appreciated to improve this How to Remove Tutorial. Speak up your mind in the comment box below.
John says
December 1, 2017 at 9:54 pm
i used the cmd solution the files apear but the shortcut stay … so i shift+del it … am i safe now ?
and something more before i remove it i accidentaly run the shortcut and mu pc blacked mu screen so i restart it … then i remove the virus (i think) … i run my bit defender and i did not detect anything i also check my registry (no strange thinks in there ) am i safe? should i do anything else ?
I.C Tiempo says
If you followed the Shortcut virus remover guide correctly, I am pretty sure that you are very safe now.
Emjay says
a good instruction… all shortcuts are gone… it really help and thank you!
Anand says
Just use a Linux bootable cd like ubcd or whatever Just plugin your usb drive and you can see a folder with all your files Folder wont have any name, Remove all crap outside this folder use delete, The click open the folder and cut and paste everything to outside this no name folder, Delete the virus crap folder and you are done!!!
I.C Tiempo says
Thanks for the input Anand but for those who are not familiar with linux, the easiest way is to follow the steps above on how to remove shortcut virus easily and effectively.
Daniyal Nafees says
WOW!!! My issue is solved as soon as I completed step 1 of running Trojom remover. Hats off. Thanks a lot.
Johnny says
Very Helpful!
I used the CMD method and all my files in my SD card are recovered 🙂 Please keep up the good work. This is really helpful guide about shortcut virus.
I.C Tiempo says
Hi Johnny,
Thanks for that wonderful comment and I am happy that shortcut virus is now gone in your SD card.
puteri says
it say ‘attrib’ not as recognizes as an internal
what should i do? :'((((
I.C Tiempo says
Hello Puteri,
It means you miss something, please be careful with space. You should type this way, attrib f:*.* /d /s -h -r -s. I hope that helps, so that shortcut virus will be removed.