Travel Fans
Go Back   Computer Juice Computer Software Virus, Spyware & Security

Register

 Default 

Recycler Virus




Reply
 
Thread Tools
  #1  
Old 11th Nov 2008, 01:55
Full Member
Posts: 69
 
Hi Evilfantasy...it's me again...i think i have a virus on my laptop it is the recycler virus and i unable to remove it
i have used norton internet security 2008, avira, and avg still it is not removed. it is both on my c and d drive. please help

here is the hijack log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:54:33 PM, on 11/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\X80le\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Pinyin IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMESC\IMSCMIG.EXE /INSTALL
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\X80le\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 5847 bytes
Attached Images
File Type: jpg virus.jpg (10.4 KB, 12 views)

  #2  
Old 11th Nov 2008, 11:09
Moderator
Posts: 7,536
 
Have HijackThis fix this entry.

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)

----------

Run this online scan.

This scanner requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.
__________________

  #3  
Old 11th Nov 2008, 15:54
Full Member
Posts: 69
 
hi evilfantasy, i am not able to run it as i am using windows vista and it is asking me to run using admin rights....
  #4  
Old 11th Nov 2008, 16:07
Donor VIP
Posts: 2,156
 
right click on the IE icon and select run as administrator.
__________________

My System: First OC

Processor(s):
Intel E2180 @ 2.85
Motherboard:
Gigabyte GA-P35-DS3L
RAM Memory:
2x1GB OCZ PC2-9200 reaper CL5
Graphics Card(s):
Gainward ATI 3850
Sound Card:
on board
Hard Drive(s):
Seagate Barracuda 7200.7 120GB
Optical Drive(s):
HITACHI DVD-ROM GD-2500
Case / PSU:
Corsair VX450
Cooling:
AC freezer7 Pro, 2x80mm, 1x90mm, 1x120mm
Network / Internet:
on board / supposedly 10Meg virgin cable
Monitor(s):
Viewsonic Vx922; Viewsonic VE702m
Operating System(s):
XP Home
  #5  
Old 11th Nov 2008, 16:33
Moderator
Posts: 7,536
 
Quote:
Originally Posted by thingie2 View Post
right click on the IE icon and select run as administrator.
Ditto. You need to launch IE under the admin privileges.
__________________

  #6  
Old 12th Nov 2008, 05:30
Full Member
Posts: 69
 
ok thanks about that.. i was wondering how come this virus is not detetected by AVG, Avira and NortonIS...this happened when i inserted a memory card and NIS detected a willy something virus and said it successfully removed...but when i checked the log of NIS there is no log for it. then thats the time i installed AVG to scan but did not find any virus then uninstalled AVG and installed AVIRA but alas no virus found...:( i'll do it later thanks evilfantasy for helping me out with this..will combofix not work with this one? and does the online scanner of ESET scans the other drive?
  #7  
Old 12th Nov 2008, 15:29
Moderator
Posts: 7,536
 
ComboFix is a specialized tool and I advise you not to use it unless instructed to by someone trained in it's use. Many things can go wrong using CF and knowing how and when to use it is very important.

You say it was when you put a flash drive in the computer?

Flash Drive Cleanup

Download Flash Disinfector by sUBs and save it to your Desktop.
  • Double-click Flash_Disinfector.exe to run it.
  • Your desktop and icons may disappear. This is normal.
  • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
  • Follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • There will be no GUI interface or log file produced.
  • Reboot your computer when done.

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.
__________________

  #8  
Old 12th Nov 2008, 18:53
Full Member
Posts: 69
 
thanks evilfantasy for the input on CF. well actually here is the sequence on what happened. i inserted one mmc to my laptop then my NIS 2008 run an auto protect versus the willy virus..after which i reformatted the card...then i inserted another mmc card again NIS run an auto protect versus the willy virus again it was said that it was removed/protected.. so i reformatted the second card...then i check by reinserting it again and there is no virus... both of those card was inserted previously in my office computer who had this virus which was not detetected by symantec what happened was it block all my program from running and they have to ghost it...now the recycler virus as i recall i did not see it during the time that i inserted the mmc i believe it was the following day that i saw it then it was a hidden folder so i tried deleting it but to no avail coz as far as i recall this was also the same virus that i have seen in our office that has been affecting USB/MMC being inserted...i'll run now the ESET and paste the log...thanks
  #9  
Old 12th Nov 2008, 18:56
Moderator
Posts: 7,536
 
No problem. Deleting Recycler files isn't very easy. Windows likes to protect them. The ESET scan should remove them though but we will have to see the log first.
__________________

  #10  
Old 18th Nov 2008, 18:10
Full Member
Posts: 69
 
Hi evilfantasy ESET was not able to detect any virus. 0 files. however i am not able to locate the log file. the recycler file is a currently a hidden folder....
Reply

Register

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus Question - Can anyone tell me if i may have a virus billozz Virus, Spyware & Security 1 2nd Apr 2009 13:58
My friends MAC has a virus...umm...yeah...a Virus... cheesepuff Virus, Spyware & Security 3 29th Oct 2008 12:58
Help Have I got a virus??? Lawlesstce Virus, Spyware & Security 2 16th Mar 2008 08:16
Recycler redden137 Virus, Spyware & Security 4 14th Mar 2008 16:31
Cannot Delete Hidden Recycler Bin In Backup File ApathyKid13 General Software Chat 2 3rd Dec 2007 01:05
Thread Tools



Translations Powered by Powered by Google
Arabic Bulgarian Chinese Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Taiwanese Thai Turkish Ukrainian

Copyright ©2006 - 2010 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2010 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.