Wednesday, August 10, 2011

Recycler ka viral locha



Well if I ask a simple question to all you readers:
How many of you like to play games???4
I think mostly everybody would reply in positive.
So let’s play a game with “RECYCLER VIRUS” today.
So all you budding Engineers be ready for a ride with RECYCLER.
Ready
Steady
Go
Welcome to the duniya of “RECYCLER”.
->RECYCLER ??????4
If you are thinking that this article has anything to do with eco-friendly environment , then change up your mind before continuing.
Before playing the game with this virus let me introduce what this virus is and actually what it does within your system.
Well to begin the discussion of The nightmare of this so called virus ”RECYCLER” to the whole computing world. It’s is almost found in everybody’s removable drive as soon as he/she uses his/her removable drive in our “NETLAB” or transfers some kind of stuff to/from others.
If I quote RECYCLER, it is to be understood by default that “autorun.inf” virus will be there. RECYCLER and autorun.inf are like jay-veeru ,ram-lakshman,or it would be better to resemble them with devil bros like ravan-khumbhkaran.
In general world it is “ Where there is will,There is a way”,but in computing world,it is “Where there is RECYCLER ,There is autorun.inf”;
Sharing with you my experiences with this virus:
Frankly speaking When I was in 1st year. I hardly knew anything about computing world compared to what I know today. My biggest fault was that I used to accumulate everything in my pendrive and keep it there for months & months. many times when I used to share my stuff with my friend and opening the same pendrive in netlab’s PC. I was many times shocked to find that I could not find my folders. When I used to tell him what happened he used to open folder options select “show all hidden folders” & even then also we could not retrieve those lost folders and on seeing the properties of my pendrive we used to think:
” where the hell are those folders gone missing? Zammen khaa gayi yaa aasaam nigal gaya unhe”. Atlast after failing all known attempts,I used to format my pendrive. This happened twice or thrice with me . I remember once I lost many around 6GB of softwares and 2nd time many E-books that I had downloaded.
Buddies kahani ki duniya se bahar aa jao ab .
From My Past Experiences: The most irritating thing about this virus is that it is hardly detected by older versions of any of the anti-virus Softwares. Even trail versions of latest anti-virus don’t detect this virus. One good thing about this virus is that it will not delete any of your files/folders from your removable drive. Now you might be thinking what non-sense am I talking, believe me or not it’s the truth & you will come to know the truth as you read this article further.
What actually is RECYCLER and What it does:
Well before starting to play a game with RECYCLER , let’s try to know what actually this virus is?, how it multiplies & and how it affects your system
To begin RECYCLER virus was derived from W32.Lecna.H worm. Autorun feature in windows which is the main part where this virus attacks. As I said earlier RECYCLER and autorun.inf are found always together. RECYCLER attaches itself to autorun.inf and creates a system hidden and read only folder in your drives. Every time as you insert your removable drive it will execute itself and start multiplying. There are cases where it has been found that this RECYCLER virus attaches itself to the malicious code from different websites. Then it helps hackers steal your personal information like passwords, credit/debit card details, and important information stored in your drives.

How to trace the existence of recycler virus in your system?
->open task manager (i.e. press ctrl+alt+del and then select task manager)
->search for CTFMON.exe process
->kill that process manually
CTFMON.exe is the process that this virus executes when it is in functional stage.
How To Retrieve Your Lost Files ?
When your desired files don’t turn up in your drive the first thing most of you might be doing is:
-> Open folder options
->Select “show all hidden files and folders”
->Click on “apply” button
But you don’t end up finding all those files in your memory drive
And if you check your properties of memory drive, you still find that memory occupied by those files is still reserved. Here I would like to recall to you that RECYCLER is not going to delete any of the files from your drive. Infact it’s a very friendly virus just because of the fact that it never destroys anyone’s data.

Now a question might be arising to all your mind that where the hell are those files. The answer to that question is:
->open command prompt i.e.cmd
->change your drive to the drive where your folder was located earlier
Suppose I had a file named ADIT in my pendrive which is my “k:\” currently
My Default command prompt looks like “c:\users\sys>

->Change your drive to pendrive “k\”;
->C:\users\sys>k:

Suppose I know that I had folder “ADIT” in my pendrive and still not visible even after applying”show all hidden folders”. Then
Type
->attrib ADIT
Press enter
Now output shown above below
K:\attrib ADIT
Is
SH k:\ADIT
In the next step
Type
->attrib[space]-s[space]-h[space]ADIT
Press enter
*Note here [space] means the spacebar key on your keyboard

Now open your drive and you will be able to see your folder in your drive
There might be many times when you delete folder named “RECYCLER “ from your pendrive it might not delete permanently ar many times it is hidden(you can’t see this folder
So type
->attrib RECYCLER
Press enter

Now here is the output of above command as
SHR K:\RECYCLER
Now type
->attrib[space]–s[space]–h[space]–r[space]RECYCLER
* note: [space] is spacebar key on your keyboard
Now shift+delete RECYCLER folder from your drive

Same procedure is to be followed with autorun.inf virus as it was with RECYCLER
In general if the output
Suppose output has ABC and your path of file/folder
Where
A=S or H or R
B= S or H or R
C= S or H or R
Here S=System
H=Hidden
R=Read only attribute
Type:
In general :“->attrib –a –b –c filename/foldername”
Hoping many would be get benefit from this article and you all would be victorious fighting this greater devil RECYCLER in this game.
For more on this topic:

I would like to end up this article with the caution lines written HEX11(Vandit bhaiya) in his article “Vandy’s Experience With Virus”:
“A computer professionals employees must wash his hands with dettol after removing a Virus from his system.”
So all you readers remember to wash hands with dettol after killing this devil virus “RECYCLERS” & follow HEX11’s advice otherwise he as a owner won’t allow you to login to this website again.
Kidding haa!!!!!!!!!
There is nothing like that
Stay connected for more articles like this one.
Good bye>>>>>>