View Full Version : recycler[ a BIG HELP]
kEnzHin 9th Jul '07 Mon, 13:48 guysm bk8 sa tuwing i-insert ku ung mmc ku sa pc via card reader, may nagakroon ng recycler na folder? may files sa loob din.. malaki eh, 20MB ung size.. system file xa, kaya hnd ku kta sa kng na insert ku na mmc ku sa card reader.. pag balik ku sa phone i delete ku den i balik ku namn sa pc, nag karoon ulit.. kasam na ung ravmon.exe, ravmon.log, etc... kakainis eh, hnd ku malgay ibang files ku aksi FULL MEM xa... paanu to? suggestion pls..
OhNow3P 9th Jul '07 Mon, 13:54 saksak mo MMc mo, tapos right click ka sa recycle bin. tapos click mo properties...
check mo configure drives automatically tapos ayusin mo na lang dun.
hindi ko sure kung eto talaga fix sa problema mo pero its worth a try.
good luck.
jeff3_16 9th Jul '07 Mon, 13:54 .... ganyan din sa kin eh... ginagawa ko na lang is dinedelete ko n lang yung recycler na folder using fexplorer, pati na rin yung file na autorun.exe sa E:\ :)
ahhhhh... try ko nga rin,, kala ko kasi virus yun,, hihi
jovrea27 9th Jul '07 Mon, 13:59 ^na-experience ko rin yan ganyan... autorun.exe pati nga exiplorer.exe ba un?
delete lang using FExplorer...
jong-jong 9th Jul '07 Mon, 14:00 bro parang recycle bin yan xa!!
lahat ng dinidelete mo sa mmc habang nakakonek sa pc ang phone mo using ur phones usb cable e dun mapupunta, pero kung card reader gamit mo e walang folder na macrecreate.
2 folder yan ddb, ung recycler tsaka system volume information.
kung gusto mo yun mwala talaga, (pero d talaga yan mawawala, lalo na pg ngdedelete ka)
ishow mo lang ung hidden files tapos delete mo ung recycler na folder everytime na meron kang dinidelete sa mmc
ex.
me dinilete kang files sa images, after mo idelete, ung recycler naman ang idelete mo
or pde din na ialgay mo sa adres bar,
itype mo ung directory ng mmc tapos sulat mu ung recycler, makikita mo ung laman tapos pde mo na delete talaga
jeff3_16 9th Jul '07 Mon, 14:11 try mo po to kung pwede siya..
iinsert mo yung mmc mo via card reader, then connect mo sa pc...
then right click mo yung recycle bin, tas properties...
then click mo yung configure drives indpendently, tas click mo yung tab kung saang drive yung mmc
tas click mo yung do not move files.......
sana magwork siya.. hihi
jetaw03 3rd Aug '07 Fri, 15:19 hindi b virus un?
hzel_ 28th Sep '07 Fri, 21:17 ung autorun.exe yata and yang recycler na yan mgkasama ata sila.......nung pagconnect ko ng fone ko sa pc nmin nadetect ung autorun.exe as a virus pero ewan lang if virus din xa for phone
dreison27 5th Nov '07 Mon, 19:42 virus po yan ng computer...nainfect yan cguro ng pinagkonek mo xa sa computer...hindi mo bazta bazta madedelete sa card reader kc dinidetect ng bawat isa kung may nadelete sa kanila tapos gagawa sila nung nadelete na file nila...tama suggestions nila use fexplorer sa CP...kc hindi gagana ung virus sa OS ng phone dahil iba ung OS ng phone sa computer..
scan mo for virus ung computer mo...infected na rin cgurado yan...pati ung virus na komokopya ng folder at milalagyan ng .exe eh virus din yon...so use updated antivirus
:thumbsup:
aytimano 5th Nov '07 Mon, 19:53 Mapayo ko lang bro, e2 gamitin u, believe me. Nod32 Anti Virus, tanggal yan.
Link (http://symbianize.com/showthread.php?t=17328&highlight=nod32)
hzel_ 5th Nov '07 Mon, 19:55 burahin mo nalang manually using fexplorer or sysexplorer kasi ung fone ng kapatid 6680 matagal nang my recycler di nya denidelete aun lately bgla nlang ngrerestart ng kusa fone within cguro mga 10secs interval.....tapos nung nadelete na ung recycler aun ok na xa
dreison27 5th Nov '07 Mon, 20:37 thnx bro...mas okie ba kaysa avg ung nod32?kc parang d madetect ng avg ko eh kahit updated...try ko nga eto...thnxz uli :excited::excited:
fragile 6th Nov '07 Tue, 02:09 try mo muna tanggalin sa main disk mo by search recycler folder tpos shift + delete.. then dun na sa fone mo shift + delete din..ganito ginawa ko sakin eh.. basta bago mo gawin yun hanapin mo muna lahat ng recycle na folder...:salute:
jopo274 6th Nov '07 Tue, 08:33 tama poh cla..its a virus within ur pc...so u have to update ur anti-virus of ur pc and ur cp...to be sure...
aga_cruz 6th Nov '07 Tue, 08:58 format mo na lang po ang memory card mo,,,, tpos update mo lang ang anti virus ng pc mo
sana po makatulong tnx po
fragile 6th Nov '07 Tue, 09:36 tama poh cla..its a virus within ur pc...so u have to update ur anti-virus of ur pc and ur cp...to be sure...
bro bale pag nakita mo na yang recycler sa pc mo at fone mo sure na anjan na yan..
ang ginawa ko nga jan para mabura ay force delete..
1.explorer>tools>folder option>
tpos hanapin mo yung display protected operating system file..tpos i display mo wag hide...
2. start>search>"recycler">view>pag nasearch na "shift + delete" mo ung folder. wag mong kakalimutan yung "shift"..
3.ung sa MMC mo ganun din.. start>search>"recycler">view>pag nasearch na "shift + delete" mo ung folder. wag mong kakalimutan yung "shift"..:thumbsup:
leomclay 6th Nov '07 Tue, 21:09 tol worm yan isang klase ng virus. ang trabaho ng virus nayan eh gumwa ng gumwa ng file, inshort mag parami hanggang mapuno nila ang kinalalagyan nila. tama advice nila gumamit ka ng anti virus sa PC mo at try mo scan makikita mo virus yan.
gitaristah 6th Nov '07 Tue, 21:26 Tsong hindi mo yan matatanggal sa phone mo kung pati ung comp mo meron HEHE!! mag anti-virus ka muna sa comp mo saka mo burahin sa phone mo o kya sa anti virus mo ipabura... ganyan rin nangyari saken dati HEHE!!
hzel_ 7th Nov '07 Wed, 12:20 pwd xa mabura sa fone....via using FExplorer or SysExplorer......do mo kelangan ng pc noh :kilay: :kainis:
arwin 7th Nov '07 Wed, 12:29 tol, scan mo lng ung memorycard mo dun sa antivirus mo sa pc mo,, maaalis un.. virus yan eh.. ung iba trojan.. ahihi ;) brkada ko naka expirience na nang ganyan,, sinaksak sa ibang pc ung memorycard..
hmx_ryan 7th Nov '07 Wed, 15:28 Hi, infected ang SCVHOST.EXE ng PC mo na pinaglalagyan ng MMC... Follow this steps that I posted in HERE (http://www.symbianize.com/showpost.php?p=157548&postcount=7)
After ma-clean yung PC mo, ikabit mo ulit yung MMC mo sa PC then search mo sya sa Drive mismo ng MMC ang *.exe
Check mo yung mga nkikitang File sa MMC kung sya ay may name kagaya ng Folder kung saan sya nakita...
Example:
System.exe>>> nakita sya sa MMC Drive:/System/
dreison27 7th Nov '07 Wed, 16:32 eh panu yun baka kelangan ng OS ung scvhost.exe na process...at minsan maraming scvhost.exe at pagkaalam ko kelangan ng system un ng pc mo...so is it safe to terminate this process...kc inisip ko na rin na KILL process eh pero baka mali MApatay ko hehehe:thumbsup:
taongtuladmo 7th Nov '07 Wed, 20:59 ravmon is a virus e1 ko lang kung anong epekto nito sa phone
dreison27 7th Nov '07 Wed, 21:07 walang epekto sa phone un...kc a virus is also a computer program...and a phones OS is different from a PC kaya d makakaapekto...everytime na lalagay mo ung mmc and reader sa infected pc eh...ung may recycler na lalabas at parang recycle bin din un kaya ung mga deleted files eh pupunta dun sa recycle hanggang mapuno ung MMC mo...un...effect nya...pero madali lang delete sa phone...d xa magreresist sa deletion...:thumbsup::thumbsup:
hmx_ryan 8th Nov '07 Thu, 07:53 eh panu yun baka kelangan ng OS ung scvhost.exe na process...at minsan maraming scvhost.exe at pagkaalam ko kelangan ng system un ng pc mo...so is it safe to terminate this process...kc inisip ko na rin na KILL process eh pero baka mali MApatay ko hehehe:thumbsup:
Don't worry, I-fi-fix yan ng SDFix in the safemode
walang epekto sa phone un...kc a virus is also a computer program...and a phones OS is different from a PC kaya d makakaapekto...everytime na lalagay mo ung mmc and reader sa infected pc eh...ung may recycler na lalabas at parang recycle bin din un kaya ung mga deleted files eh pupunta dun sa recycle hanggang mapuno ung MMC mo...un...effect nya...pero madali lang delete sa phone...d xa magreresist sa deletion...:thumbsup::thumbsup:
Anung walang epekto? paginilagay mo ang MMC mo sa infected na PC, lahat ng Folder mo ay malalagyan ng [name of the folder].exe... What does it mean sa phone mo, syempre, mauubos yung disk space ng MMC mo..kaya ganun, dapat mawala yan sya sa PC...
dreison27 8th Nov '07 Thu, 14:33 Don't worry, I-fi-fix yan ng SDFix in the safemode
Anung walang epekto? paginilagay mo ang MMC mo sa infected na PC, lahat ng Folder mo ay malalagyan ng [name of the folder].exe... What does it mean sa phone mo, syempre, mauubos yung disk space ng MMC mo..kaya ganun, dapat mawala yan sya sa PC...
yun nga ibig ko sabihin...ung infected mmc eh pagsinaksak sa ibang pc...mainfect din pc...pero sa phone ung effect lang eh ung disk space nga...uubusin nya...tsaka some info din pla..if nakahide ung file extension ng mga files sa pc mo eh aakalain mo na folder nga ung virus katulad nito my documents pero pag naka show file extensions eh makikita mo na ung .exe like this my documents.exe
....:thumbsup::thumbsup:
rocarobin 11th Nov '07 Sun, 15:06 Helpful Removal Tools: 122kB Only.
It removes 5 new common viruses(worms,spyware) namely: New Folder (Sohanad v1n2), eXiPlorer, Recycler (inFo_U), WS / TTMS /FS Vb Script.
A USB Virus Shield Called UvShield Anti Virus (Worm, Spyware, Malware, Trojan)
Copy paste the link below: OR: Click it: OR: Open a New Tab:
www.mediafire.com/?71lwtl1v3gj
A program to shield a computer from infected USB disk. 122kB Only
Its a Memory Resident Program, Unless if you remove it in the task manager.
Use it for FREE.
bighorn57 12th Nov '07 Mon, 21:24 the Recycler virus also infected my ipod. ngayon hindi ko na ma-access yung
main directory nya using the open command at windows explorer.
i tried using avg to heal/delete the virus pero mukhang nadamage na yung
program nya to open the ipod's main dir though i can still listen to the songs
in it. walang diperensya ung mga songs nya.
dmist24 13th Nov '07 Tue, 12:31 i bet there are 2 kinds of recycler.exe sa pagka alam ko... ang isa yung gumagawa ng .exe in every folder and yung second ay recycler.exe with u.exe and info.exe in yuor USB at systems folder.... i have the second one...hindi ko pa nga nakuha until now.. infected ng yung mem stick at flash drive ko till now.
onikage 13th Nov '07 Tue, 13:14 guys sa usb if infected na ng recycler. Try nyo to back up nyo muna yung files ng usb sa pc din format nyo. ganun ginwa ko sa makulit na recycler it's a worm i think.
dmist24 13th Nov '07 Tue, 18:24 solve ko na to mga guys heto yung name ng virus na naka affect sa akin WORM_SMALL.HYN , yan name nya sa trendmicro.. all i did was follow the steps in there site. heto yun.
Arrival, Installation, and Autostart Technique
This worm arrives on a system as a file downloaded from the Internet by an unsuspecting user when visiting a malicious Web site. It may also be dropped by another malware.
Upon execution, it drops a copy of itself using the file name SVCHOST.EXE in the %Windows%\system folder.
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
It creates a folder named _sv_CMD_ in the Windows system folder and attempts to drop another copy of itself as U.EXE.
It then modifies the following registry entry to automatically execute its dropped copy at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Userinit = "userinit.exe, %Windows%\system\svchost.exe"
(Note: The default value data for the said entry is "%System%\userinit.exe, on Windows 2000, XP, and Server 2003, and "userinit.exe,nddeagnt.exe" on Windows NT. %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Propagation via Removable Drives
This worm propagates via removable drives. It does the said routine by creating the folder RECYCLER in all available removable drives.
It then drops copies of itself in the created folder as the files INFO.EXE and U.EXE. It also drops a text file named DESKTOP.INI in the same folder. Furthermore, it drops an AUTORUN.INF file in the root folder of the removable drive to automatically execute the dropped copy when the drives are accessed. The said file contains the following strings:
[AutoRun]
open=
shell\open\Command=RECYCLER\INFO.exe
shell\open\Default=1
shell\explore\Command=RECYCLER\INFO.exe
MANUAL REMOVAL INSTRUCTIONS
Terminating the Malware Program
Since this malware uses a file name that is also the file name of a legitimate process, it is necessary to use third party process viewers such as Process Explorer, to isolate the malware process itself.
If the process you are looking for is not in the list displayed by Process Explorer, proceed to the succeeding solution set.
1. Download Process Explorer.
2. Extract the contents of the compressed (ZIP) file to a location of your choice.
3. Execute Process Explorer by double-clicking procexp.exe.
4. In the list of running programs*, locate the malware file(s) detected earlier.
5. Right-click the malware process, and choose Properties.
6. Check if the value for the Current Directory is the same as the directory where the detected file(s) is located.
7. If yes, then right-click on the malware process, and click Kill Process Tree.
8. Close Process Explorer.
*NOTE: On computers running all Windows platforms, if the process you are looking for is not in the list displayed by Process Explorer, continue with the next solution procedure, noting additional instructions. If the malware process is in the list displayed by Process Explorer, but you are unable to terminate it, restart your computer in safe mode.
Restoring Modified Autostart Entry from the Registry
Restoring modified autostart entries from the registry prevents the malware from executing at startup.
If the registry entry below is not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.
1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
2. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows NT>CurrentVersion>Winlogon
3. In the right panel, locate the entry:
Userinit = "userinit.exe, %Windows%\system\svchost.exe"
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
4. Right-click on the value name and choose Modify. Change the value data of this entry to:
* %System%\userinit.exe (on Windows 2000, XP, and Server 2003)
* userinit.exe,nddeagnt.exe (on Windows NT)
(Note: %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
5. Close Registry Editor.
Restoring AUTORUN.INF
1. Open AUTORUN.INF using Notepad on the drive where the malware was detected earlier.
2. Delete the following lines created by the malware:
open=
shell\open\Command=RECYCLER\INFO.exe
shell\open\Default=1
shell\explore\Command=RECYCLER\INFO.exe
3. Close AUTORUN.INF and click Yes when prompted to save.
Deleting the Malware Folders
1. Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
2. In the Named input box, type:
RECYCLER
3. In the Look In drop-down list, select one removable drive, then press Enter.
4. Once located, select the folder then press SHIFT+DELETE.
5. Repeat steps 2 to 4 for the other remaining removable drives.
6. In the Named input box, type:
_sv_CMD_
7. In the Look In drop-down list, select the drive that contains Windows, then press Enter.
8. Once located, select the folder then press SHIFT+DELETE.
IMPORTANT NOTE (FROM MY PERSONAL EXPERIENCE):
In my personal experience I was able to access the AUTORUN.INF by notepad but cannot SAVE it after revising the autorun.inf because it says that it's a read only file. Tried setting the removable drive folder to show all hidden files but it didn't work. I'm absolutely clueless how to save the autorun.inf (but according to a friend of mine you can access it by dos prompt ex. F:\\ attrib -r -s -h autorun.inf ) to remove the read only setting of the file... but I havent actually tried it. So, what i did after editing the registry is reformating the USB drive and my memory card (but make sure that before reformatting the USB or memory card remove the _sv_CMD folder and stop the svchost.exe process and fixing the registry or else it will just come back even if reformatted). That's the only way to stop it.
jonkimnicko 13th Nov '07 Tue, 18:42 tol, virus yan..delete mo nalang via xplore or fExplorer..di naman yan harmful sa cp kasi virus yan sa pc...iba kasi ang pagkakagawa ng virus sa cp at pc...tsaka di pa naiintindihan ng cp ang mga .exe extensions...
dmist24 13th Nov '07 Tue, 19:45 di naman yan harmful sa cp kasi virus yan sa pc
yup. i agree but it does live inside my memory card/stick of your cellphone (if your cellphone have one).. just like what happened to me... the virus went inside my memory stick. and once i plug in the mem stick in my PC.. my PC again got infected... so the only thing i did to total erase it is reformatting my memory stick through my cellphone... in that why it would not spread on the pc... coz if sa PC mo yan i-rereformat. once maplug mo yung mem stick mo... infected agad kayo... so its better reformat it thru ur phone if it does have the capability just like what i did on my w800i... kaya lng wala lahat ng pictures and mp3s ko.. pero ok lng namn..
marvzxd 24th Jan '08 Thu, 12:48 same prob din ako my recycler din isa pa di ko mainstalan ng kahit ano pati antivirus lahat din ng game sat apps di kp mabuksan ng ooperation failed pls help, any application to format sony ericson thxs
jonkimnicko 24th Jan '08 Thu, 19:48 solve ko na to mga guys heto yung name ng virus na naka affect sa akin WORM_SMALL.HYN , yan name nya sa trendmicro.. all i did was follow the steps in there site. heto yun.
Arrival, Installation, and Autostart Technique
This worm arrives on a system as a file downloaded from the Internet by an unsuspecting user when visiting a malicious Web site. It may also be dropped by another malware.
Upon execution, it drops a copy of itself using the file name SVCHOST.EXE in the %Windows%\system folder.
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
It creates a folder named _sv_CMD_ in the Windows system folder and attempts to drop another copy of itself as U.EXE.
It then modifies the following registry entry to automatically execute its dropped copy at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon
Userinit = "userinit.exe, %Windows%\system\svchost.exe"
(Note: The default value data for the said entry is "%System%\userinit.exe, on Windows 2000, XP, and Server 2003, and "userinit.exe,nddeagnt.exe" on Windows NT. %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Propagation via Removable Drives
This worm propagates via removable drives. It does the said routine by creating the folder RECYCLER in all available removable drives.
It then drops copies of itself in the created folder as the files INFO.EXE and U.EXE. It also drops a text file named DESKTOP.INI in the same folder. Furthermore, it drops an AUTORUN.INF file in the root folder of the removable drive to automatically execute the dropped copy when the drives are accessed. The said file contains the following strings:
[AutoRun]
open=
shell\open\Command=RECYCLER\INFO.exe
shell\open\Default=1
shell\explore\Command=RECYCLER\INFO.exe
MANUAL REMOVAL INSTRUCTIONS
Terminating the Malware Program
Since this malware uses a file name that is also the file name of a legitimate process, it is necessary to use third party process viewers such as Process Explorer, to isolate the malware process itself.
If the process you are looking for is not in the list displayed by Process Explorer, proceed to the succeeding solution set.
1. Download Process Explorer.
2. Extract the contents of the compressed (ZIP) file to a location of your choice.
3. Execute Process Explorer by double-clicking procexp.exe.
4. In the list of running programs*, locate the malware file(s) detected earlier.
5. Right-click the malware process, and choose Properties.
6. Check if the value for the Current Directory is the same as the directory where the detected file(s) is located.
7. If yes, then right-click on the malware process, and click Kill Process Tree.
8. Close Process Explorer.
*NOTE: On computers running all Windows platforms, if the process you are looking for is not in the list displayed by Process Explorer, continue with the next solution procedure, noting additional instructions. If the malware process is in the list displayed by Process Explorer, but you are unable to terminate it, restart your computer in safe mode.
Restoring Modified Autostart Entry from the Registry
Restoring modified autostart entries from the registry prevents the malware from executing at startup.
If the registry entry below is not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.
1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
2. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows NT>CurrentVersion>Winlogon
3. In the right panel, locate the entry:
Userinit = "userinit.exe, %Windows%\system\svchost.exe"
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
4. Right-click on the value name and choose Modify. Change the value data of this entry to:
* %System%\userinit.exe (on Windows 2000, XP, and Server 2003)
* userinit.exe,nddeagnt.exe (on Windows NT)
(Note: %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
5. Close Registry Editor.
Restoring AUTORUN.INF
1. Open AUTORUN.INF using Notepad on the drive where the malware was detected earlier.
2. Delete the following lines created by the malware:
open=
shell\open\Command=RECYCLER\INFO.exe
shell\open\Default=1
shell\explore\Command=RECYCLER\INFO.exe
3. Close AUTORUN.INF and click Yes when prompted to save.
Deleting the Malware Folders
1. Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
2. In the Named input box, type:
RECYCLER
3. In the Look In drop-down list, select one removable drive, then press Enter.
4. Once located, select the folder then press SHIFT+DELETE.
5. Repeat steps 2 to 4 for the other remaining removable drives.
6. In the Named input box, type:
_sv_CMD_
7. In the Look In drop-down list, select the drive that contains Windows, then press Enter.
8. Once located, select the folder then press SHIFT+DELETE.
IMPORTANT NOTE (FROM MY PERSONAL EXPERIENCE):
In my personal experience I was able to access the AUTORUN.INF by notepad but cannot SAVE it after revising the autorun.inf because it says that it's a read only file. Tried setting the removable drive folder to show all hidden files but it didn't work. I'm absolutely clueless how to save the autorun.inf (but according to a friend of mine you can access it by dos prompt ex. F:\\ attrib -r -s -h autorun.inf ) to remove the read only setting of the file... but I havent actually tried it. So, what i did after editing the registry is reformating the USB drive and my memory card (but make sure that before reformatting the USB or memory card remove the _sv_CMD folder and stop the svchost.exe process and fixing the registry or else it will just come back even if reformatted). That's the only way to stop it.
kung memory card ng mga mobile, pwede niyo iremove ung virus (autorun.inf, the recycler.exe and others) by using a third party file explorer gaya ng x-plore..kasi iba ang os ng phones sa pc kaya di sila gumagana sa mga mobile phones..
lucz 27th Jan '08 Sun, 16:16 ganito gawin mo tapon mo mmc mo!! den SOLVE PROBLEM mo
|