How to remove Shortcut Virus & Folder.exe Virus from System Permanently | Nagarams Blog

Wednesday, 29 October 2014

How to remove Shortcut Virus & Folder.exe Virus from System Permanently

Rate this Post:


In the last two posts we told you the simple methods to remove shortcut virus from your Pen drives and External Disks.
Irritating Virus



Post-1 : It is complete manual method which involve typing a commands in Command Prompt

Post-2 : It is a semi manual method, in which we execute few commands by simply opening
               virus removal.Bat file
  
  All the methods described in the above said posts works good if your system is clean (not effected by Virus). If your system is effected, then above said methods doesn't work at all,  because virus in the system continuously writes the Shortcut Virus definition in to the Pen Drive & updates Pen Drive with Virus.
     Shortcuts in your pen drive will irritate you even after deleting & formatting it as shown above.
     Normally, Shortcut virus definitions are written in VBScript file (.vbs format) to create shortcuts and some other autorun.inf files to modify your file attributes into "system, read-only and hidden".
     To get rid off from Virus we have to delete Virus from it's Root locations. This method of virus removal is also useful to remove Folder.exe virus. 

Let's have a look on internal places of our PC, where the root of the virus is.

.   Open any Folder, click on the Organize button and then Folder & Search option on the Folder
    options window tick on "Show hidden files, folders & drives" option and uncheck "Hide 
    protected
    operating system files".  It prompts a warning message, don't worry click "Yes" and then click OK.

.Folder options window

         Open Run window by pressing Windows key + R. 
         Type msconfig to open the system Configuration window.  
         Go to the startup tab in the 'system Configuration window' and observe the startup items 
         Look for some wscript.exe and any doubtful .exe items  in command column .
Location of Virus in regedit
Virus location in Hard disk drive

     Now see the path of the virus file in command column and Location column  and go to the
    locations and delete them. (you can open the registry by typing regedit in run )
shortcut virus location in regedit & C disk
    If you are getting the error like, the file is being used by another application,

File in use error message

   then open the Processes  in task manager by  pressing  Ctrl+Shift+Esc  key combination from
   keyboard.
   In the processes tab just scroll down to the process that you want to delete  and right click on it and
   click on end process tree.

Task manager windows
   Now delete file in C disk as fast as possible because virus may re-initiate the task again (only some
    types of virus) and process appears again in task manager and you get error same message again and
    again unless you are fast.
   After deleting all the files from above shown locations (C disk & regedit) come back to the
   System configuration window, just un-tick the process those you have deleted  and click Apply, Click
   OK, it will ask you to restart the system. Just click exit without restart.
.  Now Download  virus removal.Bat file and open it to remove the shortcuts and .vbs files from Pen
   drive & System to complete the virus removal process.


Above said process can be applied to any doubtful process in startup items to completely remove virus from your system (Take care while killing any unknown process in Task manager, killing a genuine process may trouble your system's normal operation).

Trouble doing this... feel free to contact.
Thank You
Please leave your comments

7 comments :

Unknown said...

is really helpful, i also made a video in case if someone still don't get it: https://www.youtube.com/watch?v=Qwsfdv1pZ20

Unknown said...

If you are looking for the removal process of dnsminong.exe trojan worm, then apply the above process. It really works, I have removed the same virus from my computer by the given manual steps and using automatic removal tool.

Unknown said...

If you are looking for the removal of SpeechRuntime.exe virus, then immediately remove it, because this virus has ability to corrupt the system and user's files by creating duplicate and shortcut files.

Baba Gyanchand said...

You have a good point here!I totally agree with what you have said!!Thanks for sharing your views.
Read my blog on ABOUT GUDI PADAWA 2020

Rudraksha Ratna said...

http://teehog.com/benefits-of-8-mukhi-rudraksha/

Rudraksha Ratna said...

https://2020allfestival.blogspot.com/2020/05/7saatseven-mukhi-rudraksha-benefits-and.html

Anonymous said...

https://www.atoallinks.com/2020/essential-tips-for-working-safely-at-height/

Post a Comment