When USB folders turn back into shortcuts after cleanup, the visible .LNK files are usually a symptom rather than the whole cause. The host computer, another removable drive, a startup mechanism, or a synchronization workflow may be recreating them.
First identify when the shortcuts return
The timing narrows the source. Write down the last known-clean state and test only after you have backed up important verified documents.
| When the problem returns | Most useful investigation |
|---|---|
| Immediately after connecting to one PC | Treat that computer as the likely persistence source; disconnect the drive and scan the PC |
| Only after using another shared computer | Check that machine and every removable device recently attached to it |
| After reboot or sign-in | Review startup applications, scheduled tasks, login scripts, and Defender protection history |
| After running a particular shortcut | Inspect that shortcut’s target and arguments without opening it again |
| After restoring an old backup | Scan the restored files and verify that the backup predates the infection |
Common reasons for reinfection
The Windows computer was not cleaned
Formatting or cleaning only the USB drive leaves any active process on the PC untouched. When the drive is reconnected, that process can hide folders and recreate shortcuts. Run an updated full scan. Microsoft recommends Defender Offline when you are concerned that persistent malware may hide or defend itself while Windows is running.
Another removable drive carries the same chain
A second USB drive, memory card, or external disk can reintroduce the files. Label devices as “not yet scanned” and process them one at a time. Do not move a newly cleaned drive between unverified computers.
A shortcut launches a script or command interpreter
Shortcut files can provide targets and arguments to PowerShell, Command Prompt, Windows Script Host, MSHTA, or another utility. The presence of one of these programs is not proof of malware, but an unexpected chain deserves investigation. Use the browser-local checker to recover common fields without launching the shortcut.
Only the attributes were repaired
Running attrib can reveal hidden folders, but it does not stop the program that hid them. If this was the only action taken, the original behavior can resume. Read what ATTRIB can and cannot do.
A controlled cleanup sequence
- Disconnect all nonessential removable storage.
- Update Windows and Microsoft Defender security intelligence.
- Run a full scan. If symptoms return or normal scanning cannot remove the threat, save your work and consider Microsoft Defender Offline.
- Review Defender Protection History before restoring quarantined items.
- Inspect startup applications and scheduled tasks for entries you do not recognize; do not delete system entries based only on an unfamiliar name.
- Reconnect one USB drive, scan it without opening its shortcuts, and record the result.
- Reveal hidden folders only after scanning, then copy verified documents to a clean backup destination.
- Repeat for other drives and computers rather than connecting everything at once.
When reformatting helps—and when it does not
Reformatting a confirmed removable drive can remove its current filesystem contents, but it cannot clean a separate infected computer. It also destroys evidence and may erase recoverable files. Back up only verified documents, clean the host first, and confirm the exact target drive before formatting.
Frequently asked questions
Can one infected PC reinfect every USB drive?
Yes, if an active process monitors removable storage and writes the same files or attribute changes to newly connected devices.
Why does Defender find nothing while the shortcuts return?
The cause may be outside the scanned scope, newly introduced, policy-driven, or not represented by the shortcut alone. Update definitions, scan all involved devices, and inspect persistence points.
Should I restore quarantined files immediately?
No. Review the detection, source path, and expected publisher first. Restoring the wrong item can recreate the problem.
