Shortcuts in all drives files are hidden.

Closed
Zac - Dec 24, 2015 at 02:43 PM
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Jan 5, 2016 at 04:26 PM
Please help me out in removing all the folder shortcut virus from my pc . hope you Wil do the need full..Thank u

8 responses

Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 24, 2015 at 04:54 PM
Hello,
# Download USB Fix
  • Launch it, a shortcut will be created on your desktop.

  • Choose "Clean" option.
  • A pop-up will follow
    Connect all your external data sources to your PC (Usb keys, sd cards external drives, etc...)
  • Once you're ready, click "OK".
  • While cleaning, you will lose access to your desktop, but this is normal.

The numbers of analyzed and infected elements are displayed.

# Copy/paste the report here.

Tutorial : http://www.en.usbfix.net/2014/02/usbfix-tutorial-clean-option/

Ambucias
Moderator / Virus Security Contributor

Let me know
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 24, 2015 at 05:18 PM
Thank you so much for your valuable reply sir.
Actually the virus has attacked my computer . All my files have turned into shortcuts . I can't access any of my files.There are just shortcuts in all the Hard drives of my computer . I mean all the partitions in my computer are attacked with this shortcut folder Virus.Sir I kindly request you to help me out to get back my files . Thank you once again for your valuable reply . I Wil be waiting for your valuable reply . Thank you so much
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164 > Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 24, 2015 at 05:30 PM
Have you tried USB Fix ? It will fix those shortcuts on all your drives, trust me.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 25, 2015 at 02:08 AM
Respected Sir,
This is My REPORT FOLLOWED YOUR INSTRUCTIONS BUT STILL THE PROBLEM IS NOT SOLVED

[b]############################## | UsbFix V 8.173 | [Clean][/b]

User: Homie (Administrator) # DESKTOP-HH45QKU
Updated 21/12/2015 by SosVirus
Started at 16:50:19 | 13/10/2015

Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url]
Tutorial : [url=http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/]http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/[/url]
Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url]
Live detection : [url=http://how-to-remove.us/]http://ww25.how-to-remove.us/[/url]
Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url]

[b]################## | System information |[/b]

MB: Gigabyte Technology Co., Ltd. (G31M-S2C)
CPU: Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz
RAM -> [Total : 2037 Mo | Free : 1243 Mo]
Bios: Award Software International, Inc.
Boot: Normal boot

OS: Microsoft� Windows 10 Pro (6.3.9600 64-Bit)
WB: Internet Explorer : 11.00.10240.16384
WB: Microsoft Edge : 11.00.10240.16384 (th1.150709-1700)

[b]################## | Security Information |[/b]

AV: Windows Defender [Enabled |Updated]
AS: Windows Defender [Enabled |Updated]
FW: Windows Firewall [Enabled]
SC: Security Center [Enabled]
WU: Windows Update [Enabled]

[b]################## | Disk Information |[/b]

C:\ (%SystemDrive%) -> Fixed disk # 195 Gb (185 Gb free - 95%) [] # NTFS
D:\ -> Fixed disk # 195 Gb (178 Gb free - 91%) [Awwesome] # NTFS
E:\ -> Fixed disk # 195 Gb (179 Gb free - 92%) [Entertainment] # NTFS
G:\ -> Fixed disk # 150 Gb (124 Gb free - 83%) [] # NTFS
I:\ -> Removable disk # 942 Mb (621 Mb free - 66%) [Memory card] # FAT

[b]################## | Generic Research |[/b]

Not deleted ! ... Tentative au red閙arrage... I:\燶Games\Games.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Games\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Installs\Installs.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Installs\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Others\Contacts\Contacts.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Others\Contacts\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Others\Others.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Others\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Videos\Videos.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Videos\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Pictures\Pictures.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Pictures\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Backgrounds\Backgrounds.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Backgrounds\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Presence\Presence.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Presence\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\Images.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Images\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Sounds\Digital\Digital.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Sounds\Digital\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Sounds\Simple\Simple.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Sounds\Simple\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Sounds\Sounds.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Sounds\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Private\10281e17\10281e17.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Private\10281e17\BiBiN.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Private\Private.exe
Not deleted ! ... Tentative au red閙arrage... I:\燶Private\BiBiN.exe
Restored! [D] I:\�
Restored! [D] I:\nokia_unprocessed_images_
Restored! I:\燶Games\Games.exe -> I:\Games\Games.exe
Restored! I:\燶Games\BiBiN.exe -> I:\Games\BiBiN.exe
Restored! I:\燶Games\New folder.exe -> I:\Games\New folder.exe
Restored! I:\燶Installs\Installs.exe -> I:\Installs\Installs.exe
Restored! I:\
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 25, 2015 at 05:58 AM
To help you and prescribe the remedy, I must make a diagnostic and to do so, I require a report.

1. Open this link and download ZHPDiag3 :
https://nicolascoolman.eu
(Don't be alarmed is the site is in French, it sometimes happens, the tool will take your system language and allow the download if you get a warning message, ignore it.) Click on the download button

2. Save the file on your Desktop.

3. Double click on ZHPDiag.exe and follow the installation instructions.

(For Vista, Win 7 and 8 users, click right to ensure you execute with admin right)

4. Double click on the short cut ZHPDiag on your Destktop.

5. Click on Full.

Wait for the tool to finished (maybe a long time)

6. Close ZHPDiag.

7. To transmit the report, click on this link :

https://authentification.site

8. Search the directory where you installed ZHPDiag (usually C:\desktop\zhpdiag.txt).
9. Copy the url link obtained from Speedyshare and paste it here in your reply.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 25, 2015 at 08:33 AM
~ ZHPDiag v2015.12.25.196 By Nicolas Coolman (2015/12/25)
~ Run by Homie (Administrator) (2015/10/13 21:34:43)
~ Web: https://nicolascoolman.eu
~ Facebook: https://www.facebook.com/nicolascoolman1
~ State version: No network file
~ Mode: Scan
~ Report: C:\Users\Homie\Desktop\ZHPDiag.txt
~ Report: C:\Users\Homie\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 10240)

---\\ Internet Browsers (1) - 0s
MSIE: Internet Explorer v11.0.10240.16384

---\\ Windows Product Information (3) - 3s
~ Windows Server License Manager Script : OK
~ Licence Script File G茅n茅ration : OK
Windows Automatic Updates : OK

---\\ System protection software (1) - 5s
Windows Defender (Activate)

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 15 Stepping 13, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 2086.388 MB (53% free)
System Restore: Activ茅 (Enable)
System drive C: has 189 GB () free of 199 GB

---\\ Connection to the system mode (3) - 0s
~ Computer Name: DESKTOP-HH45QKU
~ User Name: Homie
~ Logged in as Administrator

---\\ Enumeration of the disk units (4) - 6s
~ Drive C: has 189 GB free of 199 GB (System)
~ Drive D: has 185 GB free of 199 GB
~ Drive E: has 183 GB free of 199 GB
~ Drive G: has 129 GB free of 153 GB

---\\ State of the Windows Security Center (7) - 0s
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK

---\\ Search Generic System Files (24) - 1s
[MD5.A7FFEC1BD46B20FE7E293F2D9DD1C8F5] - 10/07/2015 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [4528168] =>.Microsoft Windows庐
[MD5.5DED2A3F11AE916C8F2724947E736261] - 10/07/2015 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [59392] 漏
[MD5.CAAA293DD133160DF13D95CC48FC42B9] - 10/07/2015 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [290304] =>.Microsoft Windows Publisher庐
[MD5.32A862495B7C356B9895FDD0B9023C5F] - 10/07/2015 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2741248] 漏
[MD5.536B686D86402D254C59B5DE3A575F45] - 10/07/2015 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [578048] 漏
[MD5.8DE3F0DF5BCD3AC6360AB753BD1A63DE] - 10/07/2015 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [429056] 漏
[MD5.C287D0E32771E3222A444DC527A29477] - 10/07/2015 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [680256] =>.Microsoft Windows庐
[MD5.BB5BBD0E4D04047585E4ED0F07AA51E7] - 10/07/2015 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [534064] =>.Microsoft Windows庐
[MD5.6C12C7E01A4F64E0AA9C88AF66955CC9] - 10/07/2015 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [577888] =>.Microsoft Windows庐
[MD5.8921DF6060DB5C7700AA48CB12E9EA08] - 10/07/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [28512] =>.Microsoft Windows庐
[MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - 10/07/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92672] 漏
[MD5.CA160E02F35A61C6F5C681FB4669C519] - 10/07/2015 - (.Microsoft Corporation
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 25, 2015 at 08:34 AM
Sir am losing my files..I already lost many files:(
Please help me out:(
Thank you once again
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 25, 2015 at 04:38 PM
Sorry but the report you have posted is incomplete. You must follow my instructions to the letter. You were to upload the log on Speedyshare.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 25, 2015 at 05:59 PM
Extremely sorry for that.
Sorry for the inconvenience.
http://speedy.sh/P5gmD/ZHPDiag.txt
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 25, 2015 at 06:16 PM
It okay,

I shall return on line tomorrow morning. Today is Xmas.

Try this 1.

Check whether the files are not in hidden mode. Follow the following steps.

Step 1:

Click on the below link and download the file "AutorunExterminator"

https://ccm.net/downloads/security-and-maintenance/5911-autorun-exterminator/

Extract it --> Double-click on "AutorunExterminator" --> Plug your External

hard drive now.

This will remove the autorun.inf files from your External hard drive and also from

the drives.

Step 2:

Click on "Start" -->Run --> type cmd and click on OK.

Here I assume your External hard drive as G:

Enter this command.

attrib -h -r -s /s /d g:\*.*

You can copy the above command --> Right-click in the Command Prompt and

paste it.

Note : Replace the letter g with your External hard drive letter.

Now check for your files in External Drive.

Step 3:

After that, download the Malwarebytes' Anti-Malware from the below link

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/

Update it --> Perform "Full Scan"

Note : Default selected option is "Quick Scan".

Good Luck.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 01:58 AM
Wishing you and your family health, happiness, peace and prosperity this holiday season and in the coming New Year. May the magic of Christmas fill your heart all year long.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 12:36 PM
http://speedy.sh/mzGTn/20151226-222236.jpg
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 12:38 PM
Sir am getting an error "Access Denied" in CMD..I have uploaded the pic of the error please check it out n direct me to next step . Thank you once again..Sorry for frequent Disturbance:(
0

Didn't find the answer you are looking for?

Ask a question
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 26, 2015 at 04:32 AM
Thank you Nawal

There are no malware or virus on your computer.
0
Blocked Profile
Dec 26, 2015 at 07:36 AM
Hi,

Restore/ remove your shortcut files in your PC/ laptop through diffrent steps:

Step1: Command promt
open cmd run as admin type

attrib -h -r -s /s /d H:*.*

"H" means your disk path.

After restoring your files please install antivirus and scan your total system.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 12:44 PM
http://speedy.sh/VNeZW/20151226-231152.jpg

I tried but:(
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164 > Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 04:24 PM
You have Windows 10 don't you? You are the administrator aren't you?
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 04:26 PM
Yes I am:(
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164 > Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 26, 2015 at 04:30 PM
If you click right on start button (Windows icon in left bottom corner then click left on run, then type cmd, then click ok, what can you read on the black screen?

Please don't upload a pic, just tell me what it says.
0
Nawal771 Posts 14 Registration date Thursday December 24, 2015 Status Member Last seen January 8, 2016
Dec 27, 2015 at 03:47 AM
C:\ users\Homie>
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 29, 2015 at 04:30 PM
Try this:

Now go to CMD screen, what ever you see ignore all of these.. and type G: and press enter


it change to C: to G: like G:\>
Now type

attrib[Space]*.*[Space]-r[Space]-h[Space]-s[Space]/d[Space]/s and press enter

wait for a moment

after you see G:\> in CMD screen open your drive from Explorer.. you can see one new folder without name... open it where you should see your all files and folder..
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164
Dec 30, 2015 at 05:01 PM
Saw the image you did not write the correct command which should have been:

attrib -h -r -s /s /d g:\*.*

It was my mistake

Also:

The following "How-to" should provide the solution

https://ccm.net/faq/13346-windows-delete-the-files-in-c-recycle-bin

Are you the only user on the computer and on the hard disks?
0
Yeah am only the user
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,164 > NAWAL
Jan 5, 2016 at 04:26 PM
Sorry but I have exhausted all solutions.
0