I bet you read a lot of emails, news reports, web pages, and so on about how virus’s are going to eat your PC and I bet most of the time you pay no attention. After all you have your system up to date and you have a virus scanner. You dont even think twice about sharing files via CD or USB Sticks. Well you shouldnt, after all this wont happen to you….
My daughter borrowed my USB Stick to take some homework to school, a week ago or more and I thought nothing of it. But then I started seeing AVG pick up some virus’s, this is strange for me because I NEVER have any infections and Im usualy very strict as to what I allow to run. So I did some research into what was going on, and this is what I found and how I fixed it.
The USB Stick had a recycle bin on it, not something you would even think twice about if you were not looking, but it was called “RECYCLER32″. It had no files in it, but I was suspicious. So I stuck the stick into a Linux PC I have at home and sure enough it was no recycle bin but a very well camouflaged folder hiding a file and a desktop.ini file. This was the installer, taking advantage of the autorun feature of windows set to run by default.
So I knew it was now on my PC but where? After looking at all the usual places I turned up nothing. So I went looking on the net and found a virus scanner that would finaly detect it, but the thing that got me was it was the only scanner that even knew about it, and they were boasting about it. Very suspisious to me if you know what I mean. I wont tell you what scanner it was, but if your smart you can work it out.
Using this scanner I was able to locate both the file as well as the registry setting that was running it. And this is where I had to stop, it seemed. For two nights I struggled to work out how to stop this thing, it was loading on logon and I was stuffed on how to stop it and I tried many many things.
Eventualy I booted into standard safe mode. As the virus tried to inject into the explorer shell process it crashed it. I was able to load windows explorer navigate to the recycler folder on C, get into the massive folder in there and shift delete the file Winmap32.exe and it didnt complain because finaly it wasnt running. I then hit the registry and did a search for the file name and deleted every entry with that in it, and then I did a search for Recycler, and got rid of any entry with that in it too.
Reboot, and presto, all is well. I dont know if I can call that skill or luck, but either way I removed it with no impact to the system.
Last thing was to download TweakUI and stop all autorun’s on USB drives. I did this to every PC in the house and now I feel a little safer… for now…