RECYCLER virus
Created: 08 Dec 2011 | Updated: 27 Dec 2011 | 5 comments
Really annoying, but if you try to unhide files and still don't see them, you can use both 7-zip or 7-zip portable programs to go on your flash drive or other removable media and delete a folder called RECYCLER and autorun.inf (it is ok to remove these files, but the delete is temporary). I used the avast! anti-virus and I can scan the whole computer, even the RAM. Still, it is still there. I had troubles with my flash drive, the computer not recognizing it. I just rebooted and it is ok. Also, when you get the autorun pop-up, you can see an open folder picture instead of the normal removable drive picture. This will show if you have it. It also shows up in windows explorer. Still can't completely delete it.
Discussion Filed Under:
Comments 5 Comments • Jump to latest comment
You might want to give the Norton Power Eraser a shot at removing this threat. The tool is designed to remove threats that hide from traditional AV.
http://security.symantec.com/nbrt/npe.aspx?lcid=10...
If possible submit a sample to Symantec or ThreatExpert for analysis.
http://www.symantec.com/business/security_response...
http://www.threatexpert.com/submit.aspx
Ooyala Community Manager - Take our Video Poll
Hi try disabling the autorun by follwing the below mentioned article
http://www.symantec.com/docs/TECH104447
also try the atrrib command onthe perndrive in cmd pormpt
attrib -r -h -s -a "Drive location :\*.*" \s \d
if it is a single pen drive try the below step that worked for me
Connected the pen drive copy the content to a folder in desktop and format the pendrive and then copy the contents back to the pen drive
Hello,
I see no reason stressing on the Recycler Folder and Autorun.inf. However, what is important here is the content within the Recycler Folder and the code in the Autorun.inf file.
Understand what is the Recycler folder:
http://support.microsoft.com/kb/171694
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
FYI:-
http://www.threatexpert.com/files/recycler.exe.html
Hi,
Do you mean recycler.scr?
You can try view hidden files using below command:
c:\>dir /a:h /s d >check.txt
Also SEP should detect this threat, if it's a new variation do submit the sample to Symantec.
Would you like to reply?
Login or Register to post your comment.