Hijack Log After Running SpyBot to get rid of Virtumonde

Status
Not open for further replies.
update, well it will let me move each of the "RECYCLER" folders outside of the other partitions and to the desktop, from there I can delete them...

hmm, but should I, are these folders now related to files on the other partitions?

strange, why can't I delete them unless they are moved from the other partitions? ... that would seem to mean they are being used when they are inside the other partitions.
 
One question:

That article you gave me says that these are folders that files from the emptied out recycle bin go to.

Could it be that these "RECYCLER" folders were always there but just hidden, and one of the virus programs un-hid them?

In this case, could this mean that IF I Delete the RECYCLER folder that it would have a negative impact on a data-retrieval company's ability to obtain lost data from my harddrive in the event of a failure?

Or does this just effect the stuff that's already been in the "recycle bin"?

anybody with any insight or comments? thanks!
 
thanks..hmmm, I Read it but that article doesn't seem to explain how they suddenly arrived on each of my other partitions...
They were always there and you were probably just not aware.


and I'm left still wondering whether I should delete them (they're all on my desktop now) from my desktop or should I restore them to each of the partitions from which they came?
I would suggest you restore them. They are normal for Windows XP.

That article you gave me says that these are folders that files from the emptied out recycle bin go to.
Yes

Could it be that these "RECYCLER" folders were always there but just hidden, and one of the virus programs un-hid them?
They were always there. They are normally hidden by Windows. If you tell Windows to unhide files you will see them.

In this case, could this mean that IF I Delete the RECYCLER folder that it would have a negative impact on a data-retrieval company's ability to obtain lost data from my harddrive in the event of a failure?
Absolutely not. Data recovery is an entirely different thing.

The RECYCLER folder is the recycle bin. The recycle bin on your desktop is simply a shortcut to all the RECYCLER folders in your computer. If you have a C:\ D:\ and E:\, your recycle bin shows the contents of C:\RECYCLER D:\RECYCLER and E:\RECYCLER. Having these RECYCLER folders on each drive saves the OS from having to copy a deleted file or folder from any other drive to the C:\ drive.

I would suggest you just leave them alone.
 
one more question is how do I hide them again?
Combofix should have done that as part of the uninstall routine if they were not hidden. Doesn't sound like it uninstalled correctly. But here's how you can re-hide if needed.

Click Start.
Open My Computer.
Select the Tools menu and click Folder Options...
Select the View Tab.
Under the Hidden files and folders heading select Do not show hidden files and folders.
Check the Hide protected operating system files (recommended) option.
Click OK.
 
ok thanks, one more question is how do I hide them again?


thanks for all your help Dave!


the reason I ask is because I already have the "Do not show hidden files and folders" button checked under "control panel > folder options > view"

and they recycler folders are still visible.

any ideas or suggestions? thanks! this will be my last question I hope.
 
If you right click on the folder and select properties. Is there an option to select hidden?


Indeed, thank you sir, I actually just discovered that before coming here.

Thanks again Dave, now just to let you know or anyone else: I tried to restore the "RECYCLER" folder that I moved from each partition onto my desktop, but it says that there is already another recycler folder on each partition...soo, I suppose xp restored those folders when you reboot if they are moved/deleted.


I also reduced the size of my recycle bin storage limit to 2% from the gigantic 10% which I figure 2% is big enough for a 160gb drive.



thanks again Dave!! great help!
 
Status
Not open for further replies.
Back
Top