How to remove recycler virus / autorun virus from USB flash drives

Written by Pavan Kumar on January 10, 2009

Advertisements

This virus has been widely spread these days and it has become very common that every pen drive we use will be infected by this virus. This Recycler virus / BV:AutoRun-G[Wrm] is very annoying one and even formatting the pen drive will not remove the virus. Though antivirus software is able to identify, it cannot remove the virus completely. If you delete this manually, it will again create itself and none of the virus removal tricks could work to resolve the problem.

  • Download Flash Disinfector and save on some non windows drive.
  • Double click on it and it will ask you to insert USB flash drive and click ok. Do so.

Remove usb virus with flash disinfector

  • Clicking on ok will make your desktop go blank, don’t worry, its normal.
  • It will fix the autorun.inf virus and you are done partially. Yes, its a partial solution, it will lock the autorun file and you will see some file created by flash disinfector. If you remove the file, the virus get re activated. May be some future update of our antivirus softwares will have complete fix for this.

Thanks Sai Computers.

Subscribe to RSS Feed or Get updates on your inbox:

People who liked this also read:

65 Readers responded to this post

This is very helpful. Almost all the pendrives now have Autorun virus

thanks for the info.. but i really want to ask you one thing.. i have a prob. in my blog.. i want to know what should be write thing for robot.txt file.. i am unable to make better one.. what is yours please visit my webpage and tell me robots text file for my blog.. i will really highly thankful to you and what should i do for more traffic.. i will advertise for you for free on my blog..
till now i am getting 1500 pageviews only..
please help me..
waiting for your reply

@sumit

Welcome here…. I checked your robots.txt and I wonder why you filter each and every bot. Simply allow bots to all your domain. They will crawl to the pages whose links are available. You are writing specifically for every bot and I don’t think that is necessary.
You can use google webmaster tools where you can see the crawl analysis for your blog and also analyze robots file.

Well thanks a lot , this helped me every much

http ://virusexperts. blogspot. com/

it doesn’t make my screen blank..
it doesn’t delete the virus..
any solution??

oh missed the last point

PL ADVICE TO REMOVE RECYCLER VIRUS FROM MY COMPUTER

Steps to remove recycle virus by George.A

1- Go to Wondows Explorer/Tools/Folder Options/View/ and uncheck “hide protected operating system files”

2- now look for the folder “RECYCLER” in your hard drive’s partitions and and delete it (don’t worry about delete it, windows will create it again when you delete another file or folder) so now delete it

3- find this archive “autorun.inf” and delete it, you can change the ext by .txt to see what is inside, it’s contain this information:

[autorun]
;ibiblmjgamvmodocwzjkostqzppssmxcplaynwlzhplnesfcvqiadihctztr
shellexecute=”RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com c:\”
;bgbwilfidaalxblibzdnkwlfwvnqapgqvqlcmvfvlwudeuzhkwardzyiibhmqvdcolhjqmfamdoeeepvmnhertksxrbkyergal
shell\Open\command=”RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com c:\”
;khbspqdveitzhbftkujolleshraaqinbizeahivqavweucwcigvjltmpnjdxpcbfdwzsbcdjyxjpitmizduaxbpltzcpycjpacgpzivjp
shell=Open

4- Restart your computer and you’re done.

Thank’s a lot for your help to stop the Bv wrm on my Pen drive

@George Alfonso -
I have follwed Georges instructions and I struck these difficulties.

1. I cannot delete RECYCLER.EXE. Delete raises the Error Message:
“Cannot delete Recycler : Access denied
Make sure the disk is not full or write protected and that the file is not currently in use.”
2. I cannot find an Autorun.inf containing the text George suggests.

Any other ideas? I am still trying to beat this beast.

Hello, i didn’t know what i had in my PC, but i managed to come here and download the flash disinfector. Belive me i scaned with a lot of antivirus programs and adware/malware removing tools and nothing happened, but this one really helped me. Thank you very much, good luck developing better products and hope you’ll set it to freeware as it is now.

@George Alfonso - Sorry, George. A bit of mistyping in my previous response. What I meant was that I cannot delete (any of) the folder(s) RECYCLER. They all give me the message “Access Denied”, even when I run myself as administrator.

Does anyone have any idea how to remove the virus RECYCLER.EXE from hard drives?

hi,
I found a nice anti-malware that was able to remove the virus completly from my computer.
the name is Malwarebytes’ Anti-Malware. it’s one of the top 10 app on download.com right now.

I used the folder trick before but now even if I remove it now, no autorun.inf file are being recreated anymore. The virus is completly gone. It was also able to remove recycler.exe

You should check it on http://www.download.com/windows/

BUT HOW DO I REMOVE RECYCLER FROM MY HARD DRIVES IN THE COMPUTER???

Hello guys
Use Kaspersky Antivirus to remove recycler.exe and follow the steps above to remove the autorun.ini.

take care

george i was not able to understand where kaspersky comes in….? i found i was not able to do the steps in my pc which is vista…. recycler does not show when i boot the same pc on xp

Ok, you have to download kaspersky from internet en install it in your machine,remember to uninstall all antivirus in your PC first…. I was trying to put the link here but I can’t

Take care

<i HAVE GOT KASPERSKY 8.0 LOADED NOW CAN U DESCRIBE THE STEPS IN A GREATER DETAIL PLZ

tHANKS

HARI

@HARI -

do full scan with kspersky to delete all virus, and then follow this steps

1- Go to Wondows Explorer/Tools/Folder Options/View/ and uncheck “hide protected operating system files”

2- now look for the folder “RECYCLER” in your hard drive’s partitions and and delete it (don’t worry about delete it, windows will create it again when you delete another file or folder) so now delete it

3- find this archive “autorun.inf” and delete it, you can change the ext by .txt to see what is inside, it’s contain this information:

[autorun]
;ibiblmjgamvmodocwzjkostqzppssmxcplaynwlzhplnesfcvqiadihctztr
shellexecute=”RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com c:\”
;bgbwilfidaalxblibzdnkwlfwvnqapgqvqlcmvfvlwudeuzhkwardzyiibhmqvdcolhjqmfamdoeeepvmnhertksxrbkyergal
shell\Open\command=”RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com c:\”
;khbspqdveitzhbftkujolleshraaqinbizeahivqavweucwcigvjltmpnjdxpcbfdwzsbcdjyxjpitmizduaxbpltzcpycjpacgpzivjp
shell=Open

4- Restart your computer and you’re done.

(I put the kaspersky’s link in this blog, but the admin deleted it)

I can read everything George Alfonzo wrote. Pavan can you fix that please.

Ya this is a totally new concept.This works oly for recycler nd autorun ??

Failed program

@Madhur - A simple way is to create a autorun.inf folder in the infected drive. the virus will think it has already copied itself and the antivirus does not show any warnings. Tried and Tested

use autorun eater software…….. this is free..

i tried to download this software and my avira always prompt that this software is infected by a ‘WORM/Generic.4084 [worm]‘…………. cud u archive it in winrar or zip?tnx….

@jnkz

This is really really strange thing I am seeing for the first time. I think even you cant run the file even if I archive it for you. After you open that archive, again your antivirus software may delete the file :( I think better option would be to change the antivirus application…

Guys scan with kasperky antivirus, it will solve the problem.

kaspersky will delete the virus apliacation, then you have to follow this steps.

1- Go to Wondows Explorer/Tools/Folder Options/View/ and uncheck “hide protected operating system files”

2- now look for the folder “RECYCLER” in your hard drive’s partitions and and delete it (don’t worry about delete it, windows will create it again when you delete another file or folder) so now delete it

3- find this archive “autorun.inf” and delete it, you can change the ext by .txt to see what is inside, it’s contain this information:

[autorun]
;ibiblmjgamvmodocwzjkostqzppssmxcplaynwlzhplnesfcvqiadihctztr
shellexecute=”RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com c:\”
;bgbwilfidaalxblibzdnkwlfwvnqapgqvqlcmvfvlwudeuzhkwardzyiibhmqvdcolhjqmfamdoeeepvmnhertksxrbkyergal
shell\Open\command=”RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com c:\”
;khbspqdveitzhbftkujolleshraaqinbizeahivqavweucwcigvjltmpnjdxpcbfdwzsbcdjyxjpitmizduaxbpltzcpycjpacgpzivjp
shell=Open

4- Restart your computer and you’re done.

@george alfonso

Thanks George, you are doing a good work helping people. :)

@all

I recently got to know from a friend that Nod 32 is capable of deleting the virus like it does for any other viruses. I think this would be a great news for you. But remember, Nod 32 is not for those who run their system with very low resources, it consumes more resources.

Your welcome Pavan

I recommend downlaod and activate the trial version of kasperky, http://www.kaspersky.com,
Note:guys I’m not selling you the antivirus, just I got kaspersky and its work very well against this virus.

Regards

Dear sir,
Please help me. In my computer, PDGHK.exe file is displayed every where when we click on c:\ or D:\ or anywhere. and recycler folder also. I have used AVG 8 antivirus on safe mode. But it can’t solve.
What is it’s solution ?

@Indra

I think the avg antivirus has already removed the pdghk.exe file and your autorun.inf file still calls the same file to open when you click on c or d drive.

Open notepad, File > Save As
Select all files in drop down list, and name the new file as autorun.inf and save on desktop
Now, copy the saved file and paste it in c, d drive. Now, open C, D drive and delete the autorun.inf file you just pasted. Rename the c, d drive. Hope this will solve your problem.

If you are comfortable with viewing the hidden files, you may directly delete the existing autorun files in c, d drives and whatever drive which exists on your system.

How do the pendrives get infected by the virus RECYCLER?

use >>>>>>>>>>>
autorun virus remover 2.3 (http://www.autorunremover.com)

Search for crack :)

@grafic

To remove recycler virus, there are many tools available of which only few will work. May be my readers find some use in your tool. Autorun eater is another tool to remove autorun virus.

use this mate download auto eater and likemagic virus gone lol workfor me
http://autorun-eater.10001downloads.com

There many ways to kill “recycler”…as mentioned before. There is also another way…How? Install a winrar program…after installing, view drive affected through winrar window ( you can see even masked or hidden files) …if you see recycler or system volume information….one click on “system volume information” …once it is high lighted…press “shift + delete” keys….do the same with “recycler”….try it.

Additional note: Most of this virus pass through trial version anti-virus….try to have a full version of McAfee Enterprise 8i with perpetual duration, it can help a lot….for me i scan my usb and hdd with trial versions…it give only few detection…and then i tried with the full version….i got almost 200 detections from the same drives. Try it!

Namaste Kumar! This Dartastic from Philippines

Guys
I got one problem- i cannot open my d drive, its says recycler(followed by numbers) not found. Can anyone help me out?

Hello all.

The recycler.exe virus has infected all partitions of my hard drive and has furthermore cut off my computer from accessing the internet, so I have been unable to update my antivirus programs or download Kaspersky. I managed to manually update AVG using a different computer and despite it locating and quarantining some of the recycler files and trying to follow George’s instructions, I cannot delete the Recycler folders because they are write protected and I cannot delete the autorun.inf folders because they cannot find the specified file as created by Flash Disinfector.

Help?

Thanks

@dartastic

Thanks for the inputs, that will help visitors over here….

@Deep - @jkoo

Try autorun eater, that will help you…

did u try to open to open the folder with winzip?try to open with that and then remove it.

tHiS FLsSh DiSinfeCtoR rEalLY wOrKs!!! THAKS A LOT.

Have same problem. Everytime I run my anti virus, it keep detecting autorun.inf in all my hard disk drive with Trojan and deleted, but seems to keep regenerating myself. Will see if i can totally clean it with Kaspersky Anti-Virus.
Trying to see if i can flush out the virus with this detector called Trojan Hunter.

Hi

This is vrey helpful and needy. I have tried so many thing to recover my boot sector which was infected by RECYCLER but hopeless. It has been corrected by FLsSh DiSinfeCtoR SO it is very helpful antivirus.

Rajat

Hey guys, I got this virus a couple of days ago and figured something out. It seems that the virus only infected all the hard drives that were plugged into my laptop and the time of infection, as well as my laptops hard drive. I couldn’t get rid of it so I plugged my flash drive in and put all the things I really needed on there and reformated my laptop. It seems that the virus didn’t jump over to my flash drive, since it wasn’t plugged in my computer at the time of infection. After reformating I put my flash drive back in and move my files back and the virus didn’t come with. My two externals are still infected, I was told that if I format them using a Mac it might get ride of the virus… anyone know if this will work?

@Chris

Mac and Linux are free from viruses, and hence that mostly work. If you don’t have mac, you may try using some live linux like knoppix etc.

indians now a days are the masters of IT, even my textbooks are made in india.. very impressive… im surprised..

Dr. Web Half cured the virus, but the recycler folders still remained on my hard disks.

What else? the virus though allowed me to connect to internet was not letting me install AVG or even spypot.

I had to install them in safemode and then used the spybot shredder to delete the files hidden inside the recycler folder.

That removed the virus completely.

But now it has infected another pc which has no internet connection, so I think I will give a try to autorun eater

Will keep you updated pavan

HIIII DEAR

I HAVE A NETWORKING VIRUS IN ALL MY Computers connected if gives err generic host process win32 and net stopped working within 10min of good use nad a restart is needed all again set right

after restaring . plssssss help how to remove that virus to mail vishal786bansal@gmail.com

@Wicked Sunny -

Thanks for the valuable comment. That will be surely of help for readers who have same problem. I really don’t understand why these antivirus companies still fail to give the best solution for recycler virus.

hay pavan we can delete recycler virus with the help of AVASTA antivirus i have deleted many times so inform to all your visitors instead of saying no best sol’n

@Pavan Kumar - Mac and Linux have their own virus issues. What you meant to say (unless you simply don’t know better) is that since this is a Windows-related virus, you can safely remove it from a pen drive by formatting it under the Mac OS or Linux.

I removed the Recycler virus with autorun virus this way:

1) Go to control panel–> System–> System Restore–> Turn off system restore of all drives.
2) Do disc clean up of all drives.
3) Check the system volume information folders of each drives, if they are empty or not.
These are hidden folders(protected operating system files).
To see these, go to folder options–> View–>
click on show hidden files and uncheck “Hide proected
operating System files”. Press apply and Ok.
4) If inspite of the above step, you are able or unable to see hidden files,
Go to Start–> Run–> type regedit–> In registry editor, do the following steps
to solve following problems.
a) To see hidden files, go toHKEY_LOCAL_MACHINE\sOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Advanced\Folder\Hidden\Showall ( or go to Edit–> Find–> Type showall and search).
Change the dword registry default value to 1 and checked value to 2 and confirm that both
default and checked dword registry value of “No Hidden” folder is 2.
b) To make drives open directly instead of opening in a new window or opening a search or
opening “open with”, find all the registry values “mountpoints2″ and delete them.(There may
be a “MountPointManagerRemoteDatabase” dll file in system volume information of system drive. Delete it.)
c) In registry find Recycler and delete every file in every drive (eg, RECYCLER\S-7-6-80-100015368-100013452-100001365-7286.com).
5) Go to system volume information of each folder and delete every file. If you are not
permitted to enter system volume information of system drive, then go to its properties–>
security–> Give yourself all permissions possible(administrator) and remove any user with
a question mark icon(virus– has a number string name). Then, you will be able to enter
system volume information. clean any virus file there.
6) Search all autorun files in pc and delete only those in main drives (eg; C:\autorun.ini) and
those in system volume information folders together. Then go immediately to C:\RECYCLER(don’t
delete the RECYCLER folder!! Its a system folder) and delete the virus inside. Then, go to
other drives and delete any RECYCLER folder there (NOT A SYSTEM FOLDER).

Your system is cleared of Autorun and Recycler virus…. Reboot to check if virus returns…!!

To delete the autorun and recycler viruses in flash drives, delete the viruses there and
immediately “safely remove the drive”. Then, remove the drive from pc. Fraction of a delay in
safely removing the hardware will lead to reinstallation of virus!! AND REMEMBER TO CLEAN ANY
FLASH DRIVES BEFORE CLEANING THE PC OF VIRUS OTHERWISE THE VIRUS WILL COME AGAIN FROM FLASH DRIVE
TO PC…. Enjoy…… your clean pc…. AT LAST.. don’t forget to revert step 1 & 3……..

how to remove recyler and system information…..

is this recycler and system information hormfull for our system if so plz tell me and reson why it take place…….what is autorun .is this hormfull virus…how we can ridd off……plz reply….

which antivirus you think the best one and why…..????????????????

Hello. This is how I managed to remove this stubborn little bastard. At first, I tried Eset’s Smart Security. It did remove the autorun.inf but did not remove the recycler, so eventually, it did return.

Uninstalled and tried the following other programs….PC Tools Antivirus, Comodo Internet Security, and avast Antivirus. avast was the only one that found it but could not remove neither the recycler nor the autorun.inf after repeated delete attempts.

Surprisingly…or maybe not…Avira Antivir found and repaired the files after a scan. The next step involves copying all of the data to the hard drive. Finally, perform a complete (NOT a quick) format of the pen drive.

This worked for me and I learned a lesson on which antivirus is the best out there. I now use Antivir with Outpost firewall.

@ V

That’s a good workout solution. Thanks for sharing, hope it helps readers :)

Recycler Removal Tools
Download Link:http://www.speedyshare.com/798457330.html

@ All

Tool given by Sajal looks genuine and free of viruses. I would like to have feedback from any affected user about the functionality of the tool. Could anyone please test the tool and reply if it really removes recycler virus.

Recycler Removal software is for jwgkvsq.vmx virus
download:http://www.speedyshare.com/798457330.html
coming soon with next utility software

it just means that deleted files dont get deleted

1 Blog responses for this post
Leave Your Comments Below / Trackback

About The Author

    Pavan Kumar

    Pavan Kumar completed Engineering in Electronics and Communication in the year 2008. He is very enthusiastic and keen to work on different aspects of computer, internet and mobile related fields. The articles here reflect his creativity. This blog was started as a showcase of solutions for different problems and today it has got a good reputation in the blogosphere. Read More...

© 2009 - TechPavan.com. All rights reserved.

All content provided in this site are the property of TechPavan.com and is free for non-commercial usage. Read our Privacy Policy here.

Any kind content on this site cannot be reproduced in any form without permission of the author. We are not responsible for any loss or damage which may occur due to any of our content.

Site hosted on Media Temple powerful servers. Special thanks to Hyperwebenable for kind support