When running one of these shortcut that the shortcut virus creates, means that you are running malware (malware), ie copies of the virus and it will infect your system. Once in the system, this virus will steal the user’s personal data, reduce system performance and cause all other side effects related to malware.
What is Shortcut Virus? How to remove it?
Virus Shortcut System infiltration is mainly through storage devices and data transfer such as USB drives, external hard drives and SD memory cards, or can penetrate the system through Autorun or Autoplay on Windows.
Many shortcut viruses are not detected by anti-virus software, so it is not enough to run anti-virus software. Fortunately, removing this virus is relatively simple, not very complicated. Through the article learn what is Shortcut virus? How to remove it? will help you to have more knowledge about this virus and how to deal with it.
Remove shortcut virus from external devices
If your USB drive, or external hard drive, or SD card is infected with the shortcut virus, it can spread to the devices or computers that you plug these devices into. Here’s how to remove shortcut virus from external devices:
Step 1: Plug the external device infected with the shortcut virus to the Windows computer.
Step 2: Open File Explorer (press Windows + E) and find the item Devices and drives to find the external device and note the drive letter.
Step 3: Open Command Prompt under Admin by pressing Windows + X to open the Power User Menu, then select Command Prompt (Admin).
Step 4: On the Command Prompt window, enter the external drive letter you noted in the above step and press Enter, for example if it’s drive E, type:
Step 5: Delete all shortcuts on the device with the command below:
del * .lnk
Step 6: Recover all files and folders on your device with the command:
attrib -s -r -h / s / d *. *
Comeinand attrib Used to change the properties of a specific file or directory. The other parts of the command specify which files and directories to change and how files and folders should be changed:
-S: remove the “system file” status from all matching files and folders.
-r: remove read-only status from all matching files and folders.
-H: removes the “hidden” status from all matching files and folders.
/S to apply the recursive command to all files and folders in the directory created and all subdirectories on the device.
/ d to apply the command to directories (normally attrib only processed on files).
*. * means that all file and directory names match.
After executing the commands, you might consider copying all the files and storing them to your external hard drive.
Permanently delete shortcut virus from computer
Step 1: Open Task Manager (press Ctrl + Shift + Esc).
Step 2: In Process tab, find and right-click wscript.exe or wscript.vbs, choose End Task. If you see both processes, perform the same steps for each process.
Step 3: Close Task Manager.
Step 4: Open Start Menu, enter regedit in the Search box to open Registry Editor.
Step 5: On the Registry Editor window, navigate to the following key:
HKEY_CURRENT_USER / Software / Microsoft / Windows / CurrentVersion / Run
Step 6: In the right pane, look for keys with strange names, such as odwcamszas, WXCKYz, OUzzckky, …. Then search the internet for information related to these shortcut viruses.
Step 7: Right click on each key, select Delete.
Remember to do a thorough research online about what that key is before deleting to avoid accidentally deleting important keys by mistake, which can lead to serious problems with Windows.
Step 8: Close the Registry Editor window.
Step 9: Open the Run command window (press Windows + R) and enter msconfig Click it and then click OK to open the System Configuration window.
Step 10: In Startup tabLook for strange programs that have extensions .exe or .vbs, choose one program at a time, choose Disable.
Step 11: Close the System Configuration window.
Step 12: Open a command prompt Tremor (press Windows + R), then type % TEMP% Click it and then click OK or press Enter to open the Windows Temp folder. Erase all the files and folders here.
Step 13: In the File Explorer window, navigate to the following path:
C: Users [username] AppData Roaming Microsoft Windows Start Menu Programs Startup
Step 14: Find files .EXE or .VBS and delete these files.
If the above method does not work, you can try using USBFix Free. Technically, this software supports cleaning USB drives and other peripherals, but you can use it to remove malware (malware) on system drives. USBFix Free works as an antivirus tool. However, keep in mind, back up your data first to ensure there is no data loss.
Download USBFix Free to your computer and install it here: Download USBFix Free
Note: If the drive or partition infected with the shortcut virus is the system drive (usually drive C:) there is no easy way to clean the corrupted shortcuts. On Windows 8.1 and Windows 10 you can use options reset or refresh system. On Windows 7, the only way is to reinstall Windows.
Some tips to avoid malware
Refer to the article 7 ways to protect your computer from malware ElectrodealPro to know more solutions to prevent software from attacking your system. Keep your device safe from potential threats from the internet.
If other malware is detected, refer to the article remove spywareManual, adware, adware, adware to quickly remove malicious software from your system.
The article on ElectrodealPro just explained to you what shortcut virus is? How to remove it? Hope the above article will be useful to you. Remember to share your opinion with ElectrodealPro.