Recycler
Last Updated on Wednesday, 04 July 2012 12:46 Sunday, 17 June 2012 15:31
The installers of this worm are less than a hundred kilobytes. Anti-virus programs may be able to detect it.
Files and folders found in a typical installation of this worm
Files
C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0096\Desktop.ini
C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0096\#####.exe
Folders
C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-0096
C:\Recycler is a legitimate folder for Recycle Bin in windows XP. This name is not found in Vista/Windows7
On older FAT file systems (typically Windows 98 and prior), it is located in Drive:\RECYCLED. In the NTFS filesystem (Windows 2000, XP, NT) it is Drive:\RECYCLER. On Windows Vista and Windows 7 it is Drive:\$Recycle.Bin folder.
It is a computer worm that can infect other computers in a network.
It can also infect removable drives
It connects the computer to a hacker through an IRC server
It creates a folder in the recycle bin and registers it as recycle bin. It then creates malicious EXE files in this folder. These files may not be detected by anti virus programs.
A video tutorial about how to identify and remove a fake recycle bin folder - on Youtube
| < Prev | Next > |
|---|

