c:\recycler\S-1-0-5... can't be delete

Discussion in 'Malware Help (A Specialist Will Reply)' started by vvgomez, Feb 3, 2009.

  1. vvgomez

    vvgomez Private First Class

    I ran find.bat and here is the log... Help!!! Thanks..


    Warning! This utility will find legitimate files in addition to malware.
    Do not remove anything unless you are sure you know what you're doing.

    Find.bat is running from: C:\Documents and Settings\LUcid 3d\Desktop\finditnt2000xp\Find It NT-2K-XP


    Edit by chaslang: Inline log from a tool we don't use removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Feb 3, 2009
  2. vvgomez

    vvgomez Private First Class

    I deleted the content with fileassassin, but not the folder itself named S-1-0-5... etc... wonder if that was ok or enough... please let me know... someone...
     
  3. vvgomez

    vvgomez Private First Class

    talked too soon there they are again:

    C:\RECYCLER\S-1-5-21-7358...etc...-0003\desktop.ini
    C:\RECYCLER\S-1-5-21-7358...etc...-0003\INFO2

    what are they?
     
  4. vvgomez

    vvgomez Private First Class

    Chaslang, I followed the read and run me carefully and then this instruction found in a post that have same issue

    chaslang
    MajorGeeks Admin - Malware Expert Join Date: Feb 2004
    Location: Northern New Jersey USA
    Posts: 55,982
    Thanks: 7
    Thanked 1,911 Times in 792 Posts

    Re: Where is this???

    --------------------------------------------------------------------------------

    As I said awhile ago,

    "There is some nasty malware going around that will make the Recycle Bin look empty when it is not."

    Let's see if we can eliminate at least one possible problem with it.

    Download this: http://www.thatcomputerguy.us/downl...ditnt2000xp.zip

    Extract find.bat and run it. Post the log it creates back here.
     
  5. vvgomez

    vvgomez Private First Class

    update... help please....

    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Feb 6, 2009
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Files in your system restore folders and can only be removed by toggling system restore. All of this is explained in the Read and Run First sticky ( which Chas directed you to when he edited your first post). I have now edited your last post to remove an inline HJT log.
     
  7. vvgomez

    vvgomez Private First Class

    thank you for your response... just to see if I understand you, those files are virus and I only can delete them by turning off the system restore... is that right?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They may be malware......though the desktop.ini is a normally hidden system file.

    And yes, you need to toggle system restore to remove past restore points.

    If this is all that is being reported, then go ahead and do that.
     
  9. vvgomez

    vvgomez Private First Class

    two more thing before doing that:

    I need to delete the recycler folder, or the S-1-0-5... folder and keep the recycler folder?

    what happen if I delete desktop.ini with no restore point and it was a good file?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do not delete anything.....!!!!

    Right click my computer / properties / system restore / check the box to turn off system restore / apply. Reboot and then do the same thing except uncheck the box.
     
  11. vvgomez

    vvgomez Private First Class

    ok I reboot the computer without system restore...

    the cecycle bin look empty but the c:\recycler\S-1-0-5.. etc still there...

    I have four hard drivers in my computer the four of them repet the same folder and files.

    c:\recycler\S-1-0-5.. etc
    d:\recycler\S-1-0-5.. etc
    e:\recycler\S-1-0-5.. etc
    f:\recycler\S-1-0-5.. etc

    the recycle bin is configurated to use one setting for all drivers, and is empty

    Is that ok?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have re-enabled system restore, then all is fine.
     
  13. vvgomez

    vvgomez Private First Class

    oh thanks thats a relief...

    I was infected by the google-redirect malware and in my desperation of destroy it I almost destroy the computer too. A friend sent me to major geeks forum for advice before keep deleting things.

    Do you think is necesary to post you a last HijackThis log to see if everything is ok?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What you should have posted in the beginning was the logs from running the Read and Run First instructions which would have included:
    SAS
    MBAM
    Combofix
    C:\MGLogs.zip ---> from running the C:\MGTools.exe
     
  15. vvgomez

    vvgomez Private First Class

    Sorry for that, it is not excuse but I was so crazy a couple of days ago that I messed up all those instructions... now that I am more relaxed and started reading line by line I understand what I missed... I will take the time to run all the software properly and go back to you for the last check if you are still there for help...
     
  16. vvgomez

    vvgomez Private First Class

    ...finally... here are the update logs...
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I also need the log from running MGTools --> C:\MGLogs.zip.
     
  18. vvgomez

    vvgomez Private First Class

    here...
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good..your logs are clean. Anytime you have questions about the recycler files just run CCleaner. It is the repository for deleted files and folders. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  20. vvgomez

    vvgomez Private First Class

    many many thanks for taking your time to give me a diagnostic... and very happy to use the computer again without fear... but I got a kind of surfphobia after this... hopefully your last instructions can keep me safe...

    gracias...
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds