Resycler

Discussion in 'Malware Help (A Specialist Will Reply)' started by carmello2003, Nov 13, 2008.

  1. carmello2003

    carmello2003 Private First Class

    I am going crazy trying to remove "resycler from my computer. I have looked at the old threads and tried what was instructed to no avail. I scanned with "Malwarebytes"., I did a scan of my registry for "resycler" and "Boot.com" I did a CMD Prompt "sfc /Scannow" I have 3 drives I formatted 1 and 2 files popup. "System volume Information " (which is not accessible)and "Recyled" I also deleted autorun.info or something like that. I put in all my flashdrives holding down the shift key then deleted anything on it by formatting them. all my folders (drives) open now BUT when I click on Drive "D" which is the recovery for Drive "C" it says it does not have a program assoccited with it. SOMEBODYSHOOTMEPLEASE!!!!! I also have a external 4 bay with 4 250GB drives I am afraid to access. I am a DJ and I have alot of music. I also download LOTS of movies. I know thats what I get!
     
  2. carmello2003

    carmello2003 Private First Class

    OPPS I did almost everything. After a restart I checked all the drives and they are clear, BUT I hate Norton! I don't know why I keep renewing. It lets viruses and malware in and then they want $99 to fix it, what do you think is the best all around virus protection?
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome

    System Volume Information is your System Restore points and indeed is not accessable normall unless you take ownership of that folder with your admin account, but this area is flushed when you turn off and on system restore.



    As for best Antivirus and security programs do read this guide How to Protect yourself from malware! (freebies galore, and many are much better than the paid for versions)

    But if you wish to make sure all malaware is off your PC then the below guide is good, once finished attach the logs and allow the malware experts here to review nd if needed issue you some manual removal steps

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.


    plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     
  4. carmello2003

    carmello2003 Private First Class

    Yep did that (Run Me First) thats how I got rid of the "Resycler" Thank You Very Much For Your TIme.
    By the looks of things there are alot of people including myself that benifit from this web site and we thank you. Going through some threads today I found some tricks like holding the shift key down to stop a flash drive from spreading a virus to the rest of the computer, also, sfc /scannow tool to make sure my windows files were in order. I did not know there was a "Search" on the "REGEDIT" window I always went nuts trying to follow the correct paths that was time consuming. Is there... or could we (you) make a page of shortcuts and tricks? I would consider myself much more knowledgable than the average user but there is so much! Hook A Brother up! um........Sir:-D
    Thanks
    Carmello
     
  5. carmello2003

    carmello2003 Private First Class

    I was going to start a new forum called "Tricks and Tweeks" but I didn't know what to post it under. How about a new subject under "Majorgeeks.Com - Support Forums ". I think that would be awsome. "I gotta yurnin' for some learnin'"! I was going to try it under "Lounge" but it is way to wide spread in there. Can you help us out?!
    Once again thanks for you site
    Carmello2003
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    you could upload your logs so that we can see that everything went well :)
     
  7. carmello2003

    carmello2003 Private First Class

    What do I scan it with for your logs. This is my first time (Virgin) doing this I always just figured things out for myself in the past.

    and what did you think about my "Tricks and Tweeks Page"?
    Thanks again
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you follow thru the read and run me first procedures which you have already been linked to then you will see that what is involved here is you downloading the required tools, scanning with them...and attaching the logs that they generate here to your post in this thread. That way..we get to review your logs and give you a set of instructions so that we can clean out any malware that could be hiding out in your system.

    This is not a subject for the malware forum. If you would like to discuss the opening of a new forum section here for tweaks and tricks then I suggest you contact one of the site owners :)

    Thanks
    Kes
     
  9. carmello2003

    carmello2003 Private First Class

    Here are the logs I will send the others later. I could only send 3.
    Once again thank You Very Much For Your Time and Site!
    Carmello
     

    Attached Files:

  10. carmello2003

    carmello2003 Private First Class

    Here are the other 2 if you need them. Search and destroy gave me 4 logs so I combined them in the order they were written
     

    Attached Files:

  11. carmello2003

    carmello2003 Private First Class

    I now have Norton 360 & Firewall, Search and destroy, MGTools, Combo Fix, and SuperAnti Spyware also Malwarebytes' . In "msconfig" which do I want to run and which do I not to run.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    First off, could you tell me what the below relate to? They are all found here C:\Documents and Settings\Compaq_Owner\My Documents

    1) Please disable the Guest Account through user accounts if this hasn't already been done.

    2) Please go to Add and Remove Programs and uninstall the following software:

    • Java 2 Runtime Environment, SE v1.4.2_03

    3) Please disable teatimer as it will interfere with the fix, for how to do this refer to the below link:

    How to disable Spybot's TeaTimer


    4) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    5) Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6) Now Run Ccleaner!

    7) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    8) Next I would like you to install the current version of Sun Java: Sun Java Runtime Environment

    9) Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks
    Kes13!
     
    Last edited by a moderator: Nov 16, 2008
  13. carmello2003

    carmello2003 Private First Class

    The things that were in "My Docs" I deleted. I have no idea what they wer but they were created the same time some video files were suposed to be downloaded from youtube but were never downloaded. (there was just a temp file next to each one). I am running the rest of the things you wanted now 8:35am Est time 11/18/08
     
  14. carmello2003

    carmello2003 Private First Class

    I did have a few problems. Some of the things you wanted me to delete were not there. as follows

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...c=Q404&bd=pres ario&pf=desktop

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...c=Q404&bd=pres ario&pf=desktop


    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
    Files\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"

    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

    O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    These did not exsist I assume because there were running in the startup menu at the time of the first test but were not running now.

    Also since I did tese things you asked while trying to send you a Excel Doc with a message and a pic on it excel will not insert a "Gif" or a "Jpg" from my desktop. it shuts excel down and I lose my work. I believe it is an "Active X' problem Becase of the Icon that pops up in the "Programs running" window by the clock I am attaching the Pics so you can see the before and after. I didn't do this before and I do this everyday. See file attached.
    Once again I want to thank you for your time! I am scanning my other computer that had the "resycler" on it. I will run in another thread.
    P.S. (I did not have probles with that computer but it was on there. I just deleted the Runinfo and the resyvler folder
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there.

    Could you please put the below two files into a ZIP file and attach it to your next post.


    Also please put your PC into normal startup mode with MSconfig as was requested in step 1 of the READ & RUN ME. You need to remain in normal startup mode. This was why you did not see some of the previous items.

    NOTE: Do not rerun the previous fixes though. I want to get into normal startup mode and then run C:\MGtools\GetLogs.bat and then attach the new C:\MGlogs.zip file.

    Thanks
    kes
     
    Last edited by a moderator: Nov 19, 2008
  16. carmello2003

    carmello2003 Private First Class

    Here are the files as requested
     

    Attached Files:

  17. carmello2003

    carmello2003 Private First Class

    here are the logs as requested
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Please rename the following files:

    Take off the .vir extensions and then simply move the 2 files back to the c:\windows\system32 directory.

    Thanks
    Kestrel13!
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi


    1) Please disable Spybot's Teatimer. See this: How to disable Spybot's TeaTimer

    2) Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AlcxMonitor] "C:\WINDOWS\ALCXMNTR.EXE"
    O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -

    After clicking Fix, exit HJT.

    3) Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Compaq_Owner\Local Settings\temp\

    4) Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    5) Now run Ccleaner!


    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    7) Then attach the below logs:
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!

    Thanks
    Kes13!
     
  20. carmello2003

    carmello2003 Private First Class

    Everything went well. Except 1 thing in my temp files (that didn't have todays date) would not delete. Iadhide5.dll Dated 08/11/04. Yes I remembered to run MGtools in normal startup this time, and I assume I am to run it in normal setup everytime. Question: Spybot always asks me about allowing changes when I boot to normal startup do I click "Allow Change" or not. reg stuff and web add on stuff and also some "global stuff" you may need to know exactly what they are. Let me know. also I assume I can take a shortcut to my temp files "Start>run> %temp%".
     

    Attached Files:

  21. carmello2003

    carmello2003 Private First Class

    One more thing I have Spybot running, norton 360, Spysweeper (paid version), SAS, System Machenic, all this stuff I understand you may not want to advise me on what not to run but if it was your computer what would you run and not run,
    Thank You Very Much Once Again
    Carl Restivo
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    HI there

    iadhide5.dll is related to Backweb which is used by many programs to do autoupdating. It is not worth worrying about...

    If you run Spybot search and destroy then you really should have TeaTimer disabled. It can be a resource hog and also makes removal of certain problems more difficult.

    I personally stay away from all paid for anti virus suites such as Norton360 because I find they are far too resource hungry....I would rather use freeware antivirus as I believe it does it's job just as well if not better. I personally use Avast....this software has it's own disadvantages as it gives alot of false positives....but this isn't a problem for me, I can usually spot right away when something is a FP or not....it's all a case of personal preference and what you are most comfortable with...

    AS for System Mechanic....I certainly wouldn't use this...I use Ccleaner which is the safest reg cleaner out there.....anything else I wouldn't touch.

    Spysweeper I am not familiar with so I cannot comment....
    I would certainly recommend that you to keep Malware Bytes and SUPERantispyware :)

    OK not much to do now....



    Manually delete the below leftover combofix files.


    And finally.....

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:

    Thanks
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds