If by chance you don't have any anti-virus you can download a trial version of norton anti-virus at www.cnet.com. That always works for me.
Main Topics
Browse All TopicsI am having a windows 2003 Enterprise Edition R2 machine working as file server in my network, from last few days it has got an attack with some adware which opens a browser window automatically at frequent random interval with random urls, like make money online or some hard core websites, I tried too many solutions but none of them detect that, I do not want to install any kind of software that generates a tons of log to submit (which I usually find on various forums, like install this and submit us the hijack log blah blah..), the only thing I could finda at some forum was that there should be an exe file in C:\recycler folder and some registry entries for that exe file, I found the registry entry for that exe file, but unfortunately I couldn't find that exe file to remove so removing those registry entries didn't help, if there is any direct solution like deleting some particular files without harming the OS & modify or delete some registry entries can work for me, please suggest that.
thx.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
If by chance you don't have any anti-virus you can download a trial version of norton anti-virus at www.cnet.com. That always works for me.
The reason why most of these sites ask for those logs is to have a better overview of what files/folders you have and what's created recently. Although antivirus and antispyware help remove these malware, it's never able to detect 100% of all malware infected files.
If you still don't want to use other third party tools and post logs here, then I suggest providing more details like what site it's displaying and the name of the exe file(s).
I recommend running a secondary online virus scan since these may catch other things that your main antivirus have missed. You can use the Panda ActiveScan. It won't remove the infections for the free scan, but will tell you where the possible infections are and you can always remove it manually.
download a program called malwarebytes from download.com. its free and is the BEST app i have ever used to remove adware and spyware like you are suffering from. During the install perform the database update and run a full system scan. remove anything it finds. it does have a purchase button but it is still free.
This is from my further investigations:
1. It seems like the virus entered into my system by a USB drive having autorun.inf and after searching a lot i found that its called as recycler virus and still there is no permanent solution for it, there is a utility called flash disinfector available for free that just creates a files within USB drive to stop spreading this virus. but doesn't remove that virus even.
Ok regarding the actual question I posted I found the following on my machine:
1. there is a recycler folder in my c:, which contains some files but windows doesn't explore them even if I have settings to show all hidden files, on my systems the folder under recycler are having icon as recycle bin.
2. I tried to explore that folder using Winrar, and I could see all the files and folder in the recycler folder, but even in safe mode widows doesn't allow me to delete files under there.
3. So tried to navigate through registry to see if there is any file running form this location on startup or so, I found one entry with name as "Taskman" under
HEKY_LOCAL_MACHINE\SOFTWAR
but If i delete this entry in safe mode it reappears instantly even before closing the registry editor.
So this is all outcome.
Wellington, I already tried Malwarebytes , it also doesn't detects this. :(
If you're going to post a logfile you're better off posting logfile from an OTL log. Let us know if you want to scan with OTL.
Hijackthis is not a very reliable diagnostic tool these days anymore.
TrendMicro hasn't done much improvements with their Hijackthis and a lot of nasties can now hide from the Hijackthis scan.
Did Kaspersky detect it?
Without any logs, it's hard to know exactly what files and registry entries are created with this infection as there are many infections and many variants that create the files you mentioned.
Could be this one for example:
http://www.bitdefe
O
http://vil.nai.co
HKEY
Data: %Root%\RECYCLER\S-1-5-21-4
The following file is added to the root of the drive:
Autorun.inf A folder is created with a directory name similar to the below:
%Root%\Temp[random numeral]Within this directory, the following files may be added:
Dekstop.ini [Filename similar to valid Windows
HKEY_LOCAL_MACHINE\SOFTWAR
C:\RECYCLE
Try Combofix and show us the log.
Please download ComboFix by sUBs:
http://download.bleep
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepin
Use these utils/monitors to see if they help
http://technet.microsoft.c
http://technet.microsoft.c
http://majorgeeks.com/Acti
Be careful with autoruns as you can delete entries as well as a viewer, which if you delete something that you're not supposed to can lead to serious consequences
Business Accounts
Answer for Membership
by: AswadGaziPosted on 2009-10-31 at 21:05:46ID: 25712565
Hi What antivirus are you using? What is type of adware is it?