Understand the symptom before taking action.
Practical guides for shortcut malware, hidden files, recurring USB infections and the indicators observed during ANTÍDOTO development.
Shortcut virus: what it is, why it returns and how to remove it
When folders and documents are replaced by shortcuts, the problem may be on the external drive, in Windows, or both. The first goal is…
Read guide →USB drive full of shortcuts: what to do before formatting
If your USB drive turned into shortcuts and files seem to have disappeared, formatting immediately can destroy useful data without fixing the source of…
Read guide →Hidden files on a USB drive: why they disappear and what to do
The drive still shows used space, but folders are gone? USB malware can change file attributes and hide legitimate content without necessarily deleting it.
Read guide →Does the virus return after formatting a USB drive? Here is why
If a USB drive is formatted, appears clean, and turns into shortcuts again after connecting to the same PC, the source may be Windows.
Read guide →How to tell whether Windows is reinfecting USB drives
When different removable drives become affected after passing through the same computer, Windows is worth investigating as a possible source of reinfection.
Read guide →How to recover files hidden by USB malware
If malware hid your documents, the goal is to restore visibility without running suspicious shortcuts or destroying the original data.
Read guide →USB-Explorer.exe: what it is and how ANTÍDOTO identifies it
USB-Explorer.exe is a filename observed in the malicious USB infection pattern analyzed during ANTÍDOTO development. The filename alone is not a classification.
Read guide →GPLControl.exe: Windows persistence and reinfection
GPLControl.exe was observed in the real infection pattern that led to ANTÍDOTO, associated with startup persistence in Windows.
Read guide →Start with a free diagnosis.
ANTÍDOTO shows the indicators it finds before any remediation.
