adiels
June 4th, 2008, 03:21 AM
Ok...I am not a noob, in fact I do consider myself an expert when it comes to viruses and trojans, but recently at my office I have encountered the most stealth and tough trojan/rootkit of all times.
Its the RECYCLER trojan. I have been searching for any info about this and although I have found a lot of people reporting it but no antivirus/antispyware detect it, I have used avira, avg, mcafee,kaspersky,spyware doctor, webroot spy sweeper, spybot, super antispyware and none detects it.
The problem is on 5 systems running xp pro sp2 with NTFS. FAT32 is safe.
Normally I do not need antiviruses or antispywares to remove a trojan, I know every place from where a trojan can start with windows. But there is NO place in registry I found where there is any entry for this trojan. Most of the people who are reporting about this has an autorun.exe or autorun.inf on their root drives from where this trojan is executed, but in my pc there is no such files, I have used icesword for this in case windows is unable to show me any file although I have set windows to show me even the superhidden files. But there is no such file on my root drive. When I open the recycler folder there is an icon of recycle bin with following name
S-1-5-21-606747145-1770027372-839522115-1005
or sometimes there are two icons and the second one is
S-1-5-21-606747145-1770027372-839522115-1004
when i open this recycle bin it directs me towards the normal windows recycel bin, but through ice sword I have accessed the real files inside this and they are
Info.exe
desktop.ini
Although I did manually removed the recycler folder many times, but whenever I delete ANY file the folder reappears. I have searched and searched in registry for any suspicious entry but I did'nt found one. And believe me I have searched EVERY starting point a trojan can use.
So is this the ultimate hiding machine or what??that I cannot see its registry entries even with a great program like icesword??
What is making me mad is that I cannot even find how it is starting with windows in the first place because there is no entry, no autorun file..then how is it doing this?? I have disconnected my pc from network hoping that it somehow copies itself from other computers but thats not the case, it has some file on my pc that I cannot see, antivius can't detect. One thing more when I access any of the infected pc through network although I can access the pc BUT I cannot access windows, program files and documents and settings folders, everything else like other drives is accessible. So I cannot see these folders through network and I think if and only if I can do that then maybe I will be able to see the malicious file.
I can always do a low level format and can solve this issue, but its kinda hurting my ego, I have removed so many trojans manually and now this undetectable thing is destroying my ego, besides I have read at some places that this thing does'nt go even after formatting. So I want to know what is this, why it is able to bypass antiviruses and antispywares, how is it starting with windows and so on.
My hijackthis and combofix logs are attached.
Can anyone help me??
~Logs removed per Policy (http://www.wilderssecurity.com/showthread.php?t=42148) - Ron~
Its the RECYCLER trojan. I have been searching for any info about this and although I have found a lot of people reporting it but no antivirus/antispyware detect it, I have used avira, avg, mcafee,kaspersky,spyware doctor, webroot spy sweeper, spybot, super antispyware and none detects it.
The problem is on 5 systems running xp pro sp2 with NTFS. FAT32 is safe.
Normally I do not need antiviruses or antispywares to remove a trojan, I know every place from where a trojan can start with windows. But there is NO place in registry I found where there is any entry for this trojan. Most of the people who are reporting about this has an autorun.exe or autorun.inf on their root drives from where this trojan is executed, but in my pc there is no such files, I have used icesword for this in case windows is unable to show me any file although I have set windows to show me even the superhidden files. But there is no such file on my root drive. When I open the recycler folder there is an icon of recycle bin with following name
S-1-5-21-606747145-1770027372-839522115-1005
or sometimes there are two icons and the second one is
S-1-5-21-606747145-1770027372-839522115-1004
when i open this recycle bin it directs me towards the normal windows recycel bin, but through ice sword I have accessed the real files inside this and they are
Info.exe
desktop.ini
Although I did manually removed the recycler folder many times, but whenever I delete ANY file the folder reappears. I have searched and searched in registry for any suspicious entry but I did'nt found one. And believe me I have searched EVERY starting point a trojan can use.
So is this the ultimate hiding machine or what??that I cannot see its registry entries even with a great program like icesword??
What is making me mad is that I cannot even find how it is starting with windows in the first place because there is no entry, no autorun file..then how is it doing this?? I have disconnected my pc from network hoping that it somehow copies itself from other computers but thats not the case, it has some file on my pc that I cannot see, antivius can't detect. One thing more when I access any of the infected pc through network although I can access the pc BUT I cannot access windows, program files and documents and settings folders, everything else like other drives is accessible. So I cannot see these folders through network and I think if and only if I can do that then maybe I will be able to see the malicious file.
I can always do a low level format and can solve this issue, but its kinda hurting my ego, I have removed so many trojans manually and now this undetectable thing is destroying my ego, besides I have read at some places that this thing does'nt go even after formatting. So I want to know what is this, why it is able to bypass antiviruses and antispywares, how is it starting with windows and so on.
My hijackthis and combofix logs are attached.
Can anyone help me??
~Logs removed per Policy (http://www.wilderssecurity.com/showthread.php?t=42148) - Ron~