Link to home
Start Free TrialLog in
Avatar of querten
querten

asked on

Virus Recycler.exe

picked up this virus..... saw many vairing posts....
Is there anyone who has had experiance with this virus...? It opens a hidden file on my C drive and could not be found by Symantec c:recycler ? Any help would be appereciated..!!
Avatar of jckingjc
jckingjc
Flag of New Zealand image

Hi querten,

All you need to remove Recycler.exe.

http://www.greatis.com/appdata/d/r/recycler.exe.htm
Avatar of rpggamergirl
Try any of these tools and show us the logfiles.

1.  Download and run this tool and follow the prompts:
http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe 

2.  Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

 
Or, MalwareBytes:
Download Malwarebytes' Anti-Malware to your desktop. check for Updates before scanning.
http://www.malwarebytes.org/mbam.php
ASKER CERTIFIED SOLUTION
Avatar of Mohammed Hamada
Mohammed Hamada
Flag of Portugal image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
we had this one , you want to check your system32 drive for 3 hidden alpha numerical folders and remove

check to see if there's an alphanumerical process something like 1EDF2K.EXE running and end task.

also check %userprofile%\Local Settings\Temp\E_N4\ and delete this folder.