$RECYCLE.BIN folder?

sharpnova

New member
Member
Local time
5:30 PM
Messages
66
Yesterday I got a nasty malware infection.

I followed all the instructions and thought everything was clean and back to normal.

But then I noticed something.

Some of my drives have a folder called $RECYCLE.BIN in them.

The folder is empty.

Toggling whether hidden files/folders are shown and toggline whether protected operating system files are hidden has no effect.

The folder is just there. A regular folder.

Is my windows broken? Or do I have some other infection?
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
CPU
3930k
Memory
16 GB
Graphics Card(s)
Titan
Monitor(s) Displays
Triple ASUS's
Screen Resolution
2560x1440 (times 3)
I have a $RECYCLE.BIN folder on every partition (NTFS).

If I uncheck Hide protected operating system files, i do see these folders listed in Windows (file) Explorer.
If I check Hide protected operating system files, i don't see these folders listed in Windows (file) Explorer.

To me it sounds like you still have some issues.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
Try right clicking on your "Recycle Bin" desktop icon and you should see something like this:

Recycle Bin Properties.jpg

Open an Elevated Command Prompt

Type:

RD /S /Q C:\$Recycle.bin

   Note
Replace "C:" in the above line with the drive letter shown on your machine and repeat the command for each drive letter.

So for my machine that would mean three commands for three drives.

Press Enter

Then right click desktop and choose "Refresh"

That should delete any legitimate recycle bins and recreate fresh ones but you might need to reboot for it to take effect.

After a reboot - set folder options to uhide protected operating system files and check again for these folders. Note the dates. You should be able to tell from the dates if any are not genuine.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Yep this worked.

From what I read, one of the malware removers I used has this residual $RECYCLE.BIN effect.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
CPU
3930k
Memory
16 GB
Graphics Card(s)
Titan
Monitor(s) Displays
Triple ASUS's
Screen Resolution
2560x1440 (times 3)
Okay so if you now only have one newly created recycle bin per drive then it would be best to get help with cleaning up malware remnants in the System Security section.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
All cleaned up. Thanks

Had to pay to get the cryptolocker removed but at least they did it.

For those wondering, they accepted bitcoins and I paid 3.5 btc for the unlocker.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
CPU
3930k
Memory
16 GB
Graphics Card(s)
Titan
Monitor(s) Displays
Triple ASUS's
Screen Resolution
2560x1440 (times 3)
Possible suggestion - don't know if it will work.

Boot into Safe Mode with Command Prompt. See tutorial here:

http://www.sevenforums.com/tutorials/69585-safe-mode.html

Try Option One then choose "Safe Mode with Command Prompt" in Advanced Boot Options.

If it works and the command prompt window opens type:

cd restore

Press Enter.

type rstrui.exe

Click "Next" and choose an available restore point.

Note: Using this method means that your computer may take some time to boot on the next boot and could take a long time before the restore operation either suceeds or fails. On my machine it has sometimes taken almost one hour!
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Back
Top