How to Remove Virus shortcut

How to Remove Virus shortcut. This time I will share about How to Remove Virus Shortcut which is a virus that is rather difficult to remove. Indeed, many antivirus great and good in eliminating the virus this shortcut, but usually only to lock it so that the virus does not spread every where and the actual virus shortcut is still there and not deleted from your computer pc or your flash.

Here's how to remove virus shortcut :
  • Disable 'System Restore' for a while during the cleaning process.
  • Decide who will clean your computer from the network.
  • Turn off the virus active in memory by using the tools 'Ice Sword'. Once the tools are installed, select the file that has the icon 'Microsoft Visual Basic Project' and click 'Terminate Process'. Please download these tools at
  • Delete the registry that has been created by a virus by:
a. Click the [Start]
b. Click [Run]
c. Type Regedit.exe, and click the [OK]
d. On application the Registry Editor, browse the key [HKEY_CURRENT_USER \ Software \   Microsoft \ Windows \ CurrentVersion \ Run]
e. Then delete the key that has the data [C: \ Documents and Settings \% username%].
  • Disable autoplay / autorun Windows. Copy the script below in notepad and save it as repair.inf, install the following manner: Right click repair.inf -> INSTALL
  • Delete Files parent and duplicate files are created by the virus, including the flash disk. To expedite the search process, you can use the 'Search'. Before conducting the search should show all hidden files by changing the Folder Options settings.
Do not let an error occurred while deleting the parent files and duplicate files that have been created by the virus. Then delete the master file that has the virus characteristics:
-. Icon 'Microsoft Visual Basic Project'.
-. File Size 128 KB (for other variants will have varying sizes).
-. Ekstesi file. 'EXE' or '. SCR'.
-. File type 'Application' or 'Screen Saver'.
Then delete the duplicate shortcut files that have the characteristics:
>. Folder icon or icon
>. The extension. LNK
>. File Type 'Shortcut'
>. 1 KB file size
Delete the file. DLL (eg ert.dll) and Autorun.inf file on flash disk or a shared folder. Meanwhile, to avoid the virus is active again, delete the master file that has the extension EXE or SCR first, then remove Shortcut file (. LNK).
* Unhide the folders that have been hidden by the virus. To expedite the process, please download the tools Unhide Files and Folders in

Once installed, select the directory [C: \ Documents and Settings] and folders that exist on the flash disk by sliding into a column that is already available. In the [Attributes] empty of all the options, then click the [Change Attributes].
* Install security patches 'Microsoft Windows Shell shortcut handling remote code execution vulnerability, MS10-046'. Please download the security patch at

How to Remove Virus Shortcut in flash
Random8 One of the most worms circulating in the community today. This worm was created using Visual Basic programming language without the in-pack and has a standard icon Visual Basic applications. Although the variants found to date do not indicate a destructive payload, but the emergence of new variants and the rapid diffusion should be aware.

Polymorphic Random8 have the ability to shuffle his body, various antivirus recognize it by different names, such as Poly.Agent, VB-PTV, Vobfus, Worm.VB.NZJ, and others.PCMAV recognize it as Random8 (until recently known Random8 which reached 12 variants), take one moment to duplicate the characteristics of the worm itself, which generate a random string that is always on a specific part, where the string is composed of 8 characters in the alphabet.

Random8 use as a removable disk diffusion method, beware if you have a removable disk features include:
* All on-hidden folder.
* Lots of shortcut files with the name of the folder that is hidden and add a shortcut with the name of the Documents, Music, New Folder, Passwords, Pictures, and Video.
* There are 4 (four) files with the attributes Hidden, System and Read Only ie: Autorun.inf, two *. exe files with a random name and a file with type Dinamic Link Library (. Etc.). Certain variants also create a file named x.exe.
* All of the shortcuts that are made lead to the worm files with extension *. scr.
* Some variants change the removable disk icon into the icon folder.

Hopefully this article on How to Remove Viruses These shortcuts can be beneficial to all of you who are looking for or need it. In another variant of the worm is found that makes a lot of shortcuts on falshdisk with a name consisting of 3 characters. Once the worm is active in memory, it will create two files with random names in the directory C: \ Documents and Settings \ [user name] \ [random name]. Exe.To eliminate the virus in the flash shortcut Random8 please download PCMAV Virus.
