"recycler"

Discussion in 'Malware Help (A Specialist Will Reply)' started by newg, Dec 18, 2009.

  1. newg

    newg Private E-2

    This new threat has potential to delete the data. I have lost my more than 1GB data and its has devastating effects. Little facts known about it. But it create folder same as recycle bin with couple of other folders same like that but with different names. Some facts are exist in below link. I am old user so I am aware of all the tools and process before posting any new thread.

    http://www.techpavan.com/2009/01/20/virus-removal-solution-bv-autorun-g-wrm-recycler-virus/
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a new threat. It is more than a year old. What is the purpose of your post? Do you need help cleaning a PC? If so, run our cleaning process and attach the logs.;)
     
  3. newg

    newg Private E-2

    you meant that cleaning with spybotsearch, malwarebyte... , superantispyware?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. newg

    newg Private E-2

    okay byt what about my lost data by recycler
     
  6. newg

    newg Private E-2

    nothing happened after following all cleaning process. here I am attaching logs
     
  7. newg

    newg Private E-2

    here is the attachment
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Also you are 8 months out of date with ComboFix and you do not have it installed properly. You need to download and save the current version combofix.exe to your Desktop and run a new scan. Then attach the log from it too.


    Also please tell us what problems you are currently having.
     
  9. newg

    newg Private E-2

    I have taken long time to get back but I am away from my current place to my origin place. And here the problem is similar that I have faced there. I am posting logs here.

    Newer version of combofix has deleted folder named 'recycler'. But Is that restore the data that contained in it or data also gets deleted? In one of the laptop, it shows data above 1.5 GB in folder itself, how can I get that data?
     
  10. newg

    newg Private E-2

    here is attachments with SAS logs of both laptop and desktop. And the jpg with the error that encountered.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not talk about more than one computer in a thread nor post logs for more than one computer. I now have no idea which logs are for which computer or what problems are for which computer. Each computer belongs in its own thread and the full cleaning procedure has to be run on each and a full set of logs for each need to be attached.

    Is the ComboFix log you just posted for the computer you first posted about in this thread? It does not look like it!!! And that is the one we need a current log from. Why is ComboFix being run from E:\combofix.exe ? The instructions clearly stated the ComboFix must be saved and run from the Desktop of the user account being scanned.


    You did not say when you are getting these errors? Or on which PC. If this is for a different PC, don't mention it here anymore. Post about it in a new thread for the other computer.
     
    Last edited: Jan 4, 2010
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand what you are trying to say here.

    Again I have no idea what you are asking. Is English not your native language? Can you explain what you are asking more clearly?
     
  13. newg

    newg Private E-2

    I am so sorry as I don't know that logs for only one computer should be posted in one thread. But I have posted here because problems are same in all systems. But again I am so sorry.

    I meant that I am in another city right now and not in the place where I had scanned computer.

    English is my native language.

    In the second post, I meant that folder "recycler" contains data above 1 GB, when combofix delete the folder then data also get deleted? or combofix restores data to origin folder.
     
    Last edited: Jan 5, 2010
  14. newg

    newg Private E-2

    here I have posted logs for the PC for which thread has been started.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than what has already been fixed, your logs are clean. Just do the below.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. newg

    newg Private E-2

    GOTCHA !!!

    But how can I recover lost data???
     
    Last edited by a moderator: Jan 20, 2010
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What data do you think you lost? Nothing in your logs would indicate to us what you believe you have lost. If you have really lost data, you will have to post in the Software Forum to work on trying to do data recovery. However odds are that you will not be able to recover too much since you may have already made too many changes to the PC that could have overwritten unused space formerly used by files that are now deleted.
     
  18. newg

    newg Private E-2

    thanks I have lost my some research files
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did you lose them from? Your hard disk or a removable device? You will have to post in the Software Forum to see if you can recover anything but odds are against it. Also see the below download folder.

    http://www.majorgeeks.com/downloads38.html

    Do note the Data Recovery is less and less likely the more things you change/install/modify on a PC. For the best chances at Data Recovery, the software for doing data recovery already needs to be in place before losing the data and the files need to be recovered immediately after they are deleted by mistake. If files are deleted and then other applications are installed or other files are created, chances are very high that they will use free files space formerly used by the deleted files thus making recovery unlikely. This is why backup programs exist. If you have important data on your PC, you need to back it up before it is lost. Hard disks do crash and often with no forwarning. When they crash, you will not even be able to run a data recovery program and if the data is important, you would have to spend a boatload of money getting a data recovery company to operate on your dead hard disk.
     
  20. newg

    newg Private E-2

    Here I have attached photo of my pen drive in which selected items were folders and all are more than 50 MB but now you can see the status.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm assuming you mean that the items now showing as files, used to be folders with the same names? However there is nothing I can do to help you recover any lost data. Your best bet is the Software Forum.
     
  22. newg

    newg Private E-2

    No I had not post with that intention but to point out the seriousness of the threat. The files are nothing else but folders. So yes names are same.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have uad hundreds of people here with this type infection and no one has had this problem. You may have had other issues that couple together to create unique problems for you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds