Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

RECYCLER trojan removal from USB pen drive [Solved]


  • This topic is locked This topic is locked

#1
simquero

simquero

    New Member

  • Member
  • Pip
  • 4 posts
Hi. On discovering I have a virus I followed the procedure in 'You must read this before posting...' . Malwarbytes fixed the following:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe (Trojan.Agent) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully. (Plus some stuff in the HKEY registry)
Thanks!

However, that same RECYCLER folder is also on my pen drive. I believe this Trojan is transmitted via USB, therefore if I plug my pen drive back into my computer to deal with the infected files there, will my computer be reinfected?? I found a 2006 post that said to clean the hard drive 1st then the pen drive, but didn't continue with what to do exactly. Looks like I'm dealing with the problem in the correct order at least. What should I do? Do I plug it in and run Malwarbytes full scan (specifying the pen drive only)?

Edited by simquero, 07 January 2009 - 12:23 AM.

  • 0

Advertisements


#2
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Hello, simquero, and welcome to GeeksToGo! Before I can help you, please do the following:

Please follow the steps in this topic, and post back with an HijackThis log and MBAM (Malware Byte's Anti-Malware) log if you are still having problems and I will look over the logs for you. :)

You shouldn't need a pendrive at this point, assuming you can use your infected computer and download the tools in the topic above. I will need a better look at what is in your computer before I can figure out how best to deal with your problem. :)

Edited by handhfan, 10 January 2009 - 03:56 PM.

  • 0

#3
simquero

simquero

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
As I said in my post, I already followed the steps in that topic and as a result my computer is no longer infected, BUT my USB drive still was. Since I read on the internet that this particular infection spreads via USB, I didn't want to re-infect my computer!

So since my answer began with the same info I already had, I went ahead and inserted my USB drive. I ran Malwarebytes on the pen drive but it didn't detect anything. I selected and deleted the recycler folder. I was prompted whether I really did want to delete those infected files (even though Malwarebytes did NOT detect them in the scan). After dragging to my hard drive all pen drive files I wanted to keep, I reformatted my pen drive and scanned my C drive with Malwarebytes. All is well, no re-infection, so you can close this topic.

Thanks anyway - it's nice to know help is 'there'!

Edited by simquero, 10 January 2009 - 10:51 PM.

  • 0

#4
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Do you require any more help, or should I close this topic for you? :)
  • 0

#5
simquero

simquero

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Go ahead and close - thanks!
  • 0

#6
handhfan

handhfan

    Trusted Helper

  • Expert
  • 13,659 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP