Recover Data from USB Drive Affected with Shortcut Virus
You are here:Home » Windows 8 » Recover Data from USB Drive Affected with Shortcut Virus

Recover Data from USB Drive Affected with Shortcut Virus


A very large number of computers are affected by the USB viruses when plugged in. Not all viruses can be deleted totally even by the top antivirus software. Antivirus software may detect the virus but can’t delete it from USB drive. One such frustrating virus is well known ‘shortcut virus’. When ever the USB affected with shortcut virus, every piece of data in it is shown as shortcut and it will not be opened. In case if it opens, it affects the system also there by spreading the virus to every USB plugged in to it.

Short cut virus in USB

Where has the data gone?

The data will exits in your USB drive. DO NOT FORMAT THE DRIVE AT ANY COST, YOU NEVER BE ABLE TO GET YOUR DATA BACK. Shortcut virus is considered as prank played to frighten people by showing useless shortcuts instead of data. Actually, the data is hidden in the drive, We’ll just have to unhide the data. Let’s take a look the following process to unhide the data using command prompt.

Recovering Data

Recovering the data is the hard part when it comes to shortcut virus. You may think using a data recovery software, you can easily bring back your data from your drive. You may bring your data back until there is data detected by the recovery software. Probably it can’t.

Follow this procedure I have come across in recovering the data without any harm to it from the affected USB drive.

Step 1: Press ‘Windows button + R’. This will bring up the ‘run’ command prompt. Type ‘cmd’ and press ‘Enter’. ‘Command prompt’ will be opened.

Step 2: Carefully type attrib -h -r -s /s /d j:\*.* and press ‘Enter’. ( ‘j’ is my USB drive in my case).

command-for-unhiding

Or else, type j: and press ‘Enter’. (remember ‘j’ is USB drive here). You will enter in to your USB drive. Now type the following attrib -h -r -s /s /d *.*

Step 3: Then open your USB drive. You may find the shortcuts separated from the original data. Copy your data and save it another location in your hard drive or desktop.

Step 4:  Check you data once if you could recover the entire or only some of it.

You’re done!

What happened in command prompt?

The command prompt isn’t a wizard to do this which your best ant viruses can’t. It is the hidden feature of windows family. The ‘attrib’ is the attribute command which is used to add or remove attributes to a files in a drive or folder. The parameters

-h     removes the hidden attribute for the files.
-r     removes the read-only attribute for the files.
-s     removes the system file attribute.
/S     processes matching files in the current folder and sub folders.
/D     processes folders as well.

j:\*.*  refers all files with all extensions from the USB drive.

By the way, Congratulations for recovering your data! Comment your thanks if you like this post!



14 comments:

  1. thank you sooo much you are a life saver

    ReplyDelete
  2. You are welcome Dani :)

    ReplyDelete
  3. thank you :)))))) superb !

    ReplyDelete
  4. You are welcome Grace!! Thanks for visiting!

    ReplyDelete
  5. You're welcome. Subscribe to us for more such tricks

    ReplyDelete
  6. Replies
    1. You're welcome. Subscribe to us for more such tricks

      Delete
  7. thnx bro for the help its really work...

    ReplyDelete
  8. welcome :-)

    ReplyDelete
  9. You're welcome. Please subscribe to us for more useful updates

    ReplyDelete
  10. I followed the command attrib-h-r-s/s/dg:\*.* as you suggested but it return with either 'Invalid switch' or 'not recognized as internal or external command, operable program or batch file. DO I have to space between some of the characters?

    ReplyDelete
  11. Yesh, space exists between each and every charachter

    ReplyDelete

We're happy to read your thoughts and we'd try our level best to clear your queries if asked. Let's discuss it in a better way. Please don't spam and spoil the conversation :) Thank you!!