Shortcut Virus (Creates .ink in USBs), Disabled msconfig, CCleaner, System Restore. Tried EVERYTHING, help!!!

im Moo

Estimable
Apr 10, 2015
6
0
4,510
Hello guys!

TL;DR: an USB pendrive infected me, now it creates shortcuts on usbs, also msconfig, regedit, system restore, and everything related is disabled. halp.

2 days ago, a friend of mine wanted to show me a video he was working on, so he proceeds to insert his USB pendrive, when i open it, i realize its a full USB with .inks (Shortcuts) and then i saw it was obviously infected. So i find the original video source in .Trashes/ folder, copied to my hdd, worked on it then i wanted to copy it again, and when i gave it to him, again, he sees shortcuts, then i tried with another USB pendrive, and when i open it, it starts to create shortcuts and hiding files in front of my eyes, at this point i know i was f***ed.

I start to browse for solutions online, i catch up some with msconfig and boot things, but when i try msconfig, it doesnt let me open it, its just disabled, i tried antivirus (AVAST Free, Malwarebytes safemode), it detected something in system32, rebooted, scanned, still nothing. System restore prompts up with a failure after process was successfully. I really dont know what else to do, i dont want to format yet (i dont have too much time), there should be a solution. Pleaseeee help! (Srry for my english, not my main)
 
Solution


Try Hitman Pro
http://www.surfright.nl/en/hitmanpro

and RogueKiller
http://www.adlice.com/softwares/roguekiller/

im Moo

Estimable
Apr 10, 2015
6
0
4,510
Hello USAFRet!

Im gonna make a bootable USB Kasperky Rescue in safe mode, ill write my results, thanks in advance. Anyways, i did a "boot scan" with AVAST with no reuslts, isnt that the same?
 

USAFRet

Illustrious
Moderator


Not necessarily. You need to boot directly from the AV media, whatever it is. This prevents whatever has infected you from running in the first place. Much greater chance of success.
 

im Moo

Estimable
Apr 10, 2015
6
0
4,510
No luck, i scanned with Kasperky and he didnt found nothing, i erased the C:\System Volume Information from where i read the virus stands by, then repaired using win7 cd, problem still persists. What a tough virus :/ What else should i try?
 

im Moo

Estimable
Apr 10, 2015
6
0
4,510


RogueKiller did the thing! I tried to run it and it closes inmediately so i thought someone was running from him, i booted in safe mode, ran Roguekiller and finally its over, Thank you so much USAFRet!!!
 

USAFRet

Illustrious
Moderator


Coolness.
And don't let your friend stick his thing in your system...:)