Jump to content

Shortcut Virus infection


Ugex

Recommended Posts

Hello,

 

i have a laptop that is infected by a shortcut virus.

it appears that it's the cause of a my previous problem. as per :

it also suffers from the same symptoms as the link above, with the difference that the device in this case is running windows 8.1 x64

what should i do?

 

Thank you in advance,

Ugex

Link to post
Share on other sites

is this a pirated version of Windows OS?

  • Step #1 Fix with FRST
    Make sure that you still have FRST.exe on your Desktop. If you do not have it, download the suitable version from here to your Desktop.
    •  
    • Open Notepad.exe. Do not use any other text editor software;
    • Copy and Paste the contents inside the code-box to your Notepad --
      Start
      CreateRestorePoint:
      CloseProcesses:
      EmptyTemp:
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {22043414-edf1-11e6-82a9-9cb70d287112} - "G:\HiSuiteDownLoader.exe" 
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {82a3a3fb-0f30-11e6-82a2-9cb70d287112} - "G:\HiSuiteDownLoader.exe" 
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {82a3a45e-0f30-11e6-82a2-9cb70d287112} - "G:\HiSuiteDownLoader.exe" 
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {8baa0d01-986f-11e6-82a7-9cb70d287112} - "G:\HiSuiteDownLoader.exe" 
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {8fa1cf66-077e-11e4-8264-9cb70d287112} - "G:\Windows\AutoRun.exe" 
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {8fa1cfd8-077e-11e4-8264-9cb70d287112} - "G:\Windows\AutoRun.exe" 
      HKU\S-1-5-21-742594365-2421037321-3923363439-1001\...\MountPoints2: {fa328aff-fe1c-11e3-825d-9cb70d287112} - "G:\Windows\AutoRun.exe" 
      Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\atajo.lnk [2017-02-22]
      ShortcutTarget: atajo.lnk -> C:\Users\user\AppData\Roaming\oisysn\hdnfk.exe (Microsoft Corporation)
      GroupPolicy: Restriction - Chrome <======= ATTENTION
      CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
      C:\Users\user\AppData\Roaming\oisysn\
      	End
    • Click on File > Save as...
      • Inside the File Name box type fixlist.txt;
      • From the Save as type drop down list, choose All Files
    • Save the file to your Desktop;
    • Re-run FRST.exe and click Fix;
      • Note: If FRST advises there is a new updated version to be downloaded, do so/allow this.
    • After the completion, a log will be produced;
    • Copy and Paste the contents of the log in your next reply.

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.