Log in

View Full Version : Rootkit infection?


tonko
Apr 12, 2009, 05:01 AM
I seem to have some sort of malware on my PC. Looking around at certain blogs I think it may be something called a Rootkit infection (?). Apparently not at all good. My PC has certainly slowed down recently and I noticed something that I thought I had got rid of a couple of months back has now reappeared - a folder called RECYCLER. No matter what I use to delete it, it will not go. Previously I used "Malwarebytes' and it wiped it out and the PC started performing again. It doesn't pick it up now at all, nor does AVG, even when the folder is scanned alone. Any ideas anyone?

Scleros
Apr 12, 2009, 05:26 AM
...a folder called RECYCLER. No matter what I use to delete it, it will not go... Any ideas anyone?

That folder is part of Windows NT and later Windows version's Recycle Bin. See Microsoft Support: Differences Between the Recycle Bin and the Recycler Folder (http://support.microsoft.com/kb/171694). Scans for malware may flag the folder if it contains a malware file that was deleted and then the Recycle Bin not emptied to permanently delete it.

Helljack6
Apr 14, 2009, 02:07 PM
I seem to have some sort of malware on my PC. Looking around at certain blogs I think it may be something called a Rootkit infection (?). Apparantly not at all good. My PC has certainly slowed down recently and I noticed something that I thought I had got rid of a couple of months back has now reappeared - a folder called RECYCLER. No matter what I use to delete it, it will not go. Previously I used "Malwarebytes' and it wiped it out and the PC started performing again. It doesn't pick it up now at all, nor does AVG, even when the folder is scanned alone. Any ideas anyone?

First off, stop relying on a single piece of software to catch anything and everything, if that were the case, the choices of any preventive software for computers would be limited to a very small group.

Second, in addition to your Malwarebytes, download, install and update Spybot S&D 1.6.2 and run it as well. If you need to know how to set it up, click on my link in my signature to go to my website to learn how.

Third, do a VERY thorough cleaning on your computer, steps on how to do it are found here - Keepin' it Clean - Helljack6.com (http://www.helljack6.com/clean.html)

As previously stated, Recycler is part of the NT operating file system, HOWEVER, it's not normally visible in the file structure unless you've unhid system files/folders in the folder options.

NOW, if you have any other folders similarly named, like recycled (spelled just as it's typed) then yes you have a malware infection. Recycled is part of a medium threat malware that runs a process called game.exe and infects and propagates removable media suchs as external drives of ANY kind by creating a unique autorun.inf file hidden on the drive that is directly associated with the host/target computer's C:\recycled folder.