SHOW HIDDEN FILES. Then, unchecked HIDE EXTENSIONS FROM KNOWN FILES and HIDE PROTECTED OPERATING SYSTEM.
1.From task manager, you should end the process wscript.exe
2.Go to C:\Documents and Settings\(your user name)\Local Settings\Temp
you should see kpcgrhynko.vbs file delete it, if you dont find it, leave it and go further.
3.Next Go to C:\Documents and Settings\(your user name)\Start Menu\Programs\Startup
you should see again this file kpcgrhynko.vbs. Delete it and if there is no such file as this, proceed to the next step.
4.Open your flashdrive, Delete kpcgrhynko.vbs again.
Then, delete all the shortcut files
5.If your flahdrive is G, enter this command:
attrib -h -r -s /s /d G:\*.*
You can use Quickwiper to delete those files, it works well.
Let me know what happens. I have succeeded in doing this to one of my friend's pendrive.
----------
If still you face the issue, work with your registry and do this. Make sure you take a backup before you start working in it.
Open Task Manager (Ctrl+Alt+Del) and End Process for any WSCRIPT.EXE that is currently running. (This will stop the running virus, the next steps are for preventing it from running again next time you start your computer)
Click on Start
Type REGEDIT and Tap Enter
Click on HKEY_CURRENT_USER
Click on Software\
Click on Microsoft\
Click on Windows\
Click on CurrentVersion\
Click on Run.
On the list on the right find any reference to a file that ends with .vbs and take note of were that .vbs file is located
Go to the said location and delete the .vbs file
Go back to Regedit and delete the key referencing thtat said .vbs file