SAL.xls.exe virus and resulting damage

bw587

New member
Local time
4:56 AM
Messages
8
I have been infected with sal.xls.exe virus and have removed it with AVG - latest version.

My hard disk and removable disks have a $recycle.bin and System Volume Information folder on them that is hidden and unaccessable.

I have stopped system restore and tried to delete folders. I can remove the $recycle.bin folder but not the system volume information folder. The $recycle.bin reappears.

How do I remove them?

I am running a HP Pavilion DV7 Notebook PC with a Intel Core i7 CPU Q820 1.73 GHz and 4 GB Ram


Need help as my system is slowing down. Any ideas please.

:cry:
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
Quickly download Hitman Pro and run a scan.
Products - SurfRight
Make sure you are connected to internet before you scan.
 

My Computer My Computer

At a glance

Windows® 8 Pro (64-bit)Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB...6GB DDR3 System Memory at 1,333MHz (on BD 4GB...AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
The System Volume Information stores system restore points and is undeletable.

If any or all restore points have an infection it may be best to turn of system restore and delete all restore points through Disk Cleanup - More options then when you are clean turn system restore back on and create a new restore point.
 

My Computer My Computer

At a glance

7
OS
7
I have run:
1. AVG Anti virus Free V9
2. AdAware Free V9 anti Spy and AntiRootkit
3 cCleaner V2.28.1091 (Latest)
4. AML Free Registery cleaner
5. HiJack this

I need to delete the $Recycle.bin and System Volume Information folders to clean up the disk and stop the virus reappearing.

In regedit I have set the values for Hidden files to 1 so I can see the folders but I can not delete them.

Any ideas?
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
It's undeletable from windows. One of the major benefits of dual booting linux and windows is the ability to get into protected system folders including system volume information and delete files that would otherwise be impossible to remove. It comes in very handy for cleaning out infected HDDs, with almost no chance of spreading the virus/trojan/malware to my own computer. Something to consider trying.
 
If it's undeletable from windows how can I stop it reinstalling $Recycle.Bin and how can I remove infected part of System Volume Information? I have turned off system restore.
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
The Recycle Bin folder is put there because OS files are shown in Folder Options. If you don't like it, you can Hide Protected OS files in Folder Options or disable Recycle Bin for that drive.

Right-click on the Recycle Bin and select Properties.
 

My Computer My Computer

At a glance

Windows 7 Professional x64Intel i7 2600K OC'd @ 4620 MHz16GB GSkill Sniper 2133 Mhz (4x4GB)EVGA GeForce GTX 480 SuperClocked+
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
If you dont have a system image that you can restore from, you will need to do a clean install...
 

My Computer My Computer

At a glance

64-bit Windows 8.1 ProCore(TM) i5 CPU 4330 Haswell @ 3.20GHz12.00 GBIntel(R) HD Graphics
Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
If I can get into the system volume Information folder I can delete the malicious files. However I can see the folder in Explorer but I can't access the folder. Is there a way to get into the folder. There must be a setting somewhere to grant access.
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2

My Computer My Computer

At a glance

64-bit Windows 8.1 ProCore(TM) i5 CPU 4330 Haswell @ 3.20GHz12.00 GBIntel(R) HD Graphics
Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
No Did not work. Can delete $Recycle but System Volume Information brings it back. Cant delete System Volume Information
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
Did you follow my advice?
 

My Computer My Computer

At a glance

Windows® 8 Pro (64-bit)Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB...6GB DDR3 System Memory at 1,333MHz (on BD 4GB...AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Hi Dinesh

Hitman Pro could not be run as it could not gain a internet connection. Dont know why as I am internet at same time and internet connection is good. Have noticed other malware and anti-virus programs can not access internet for updates. Could this be related??????? to problem with system volume information and $Recycle.bin.
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
Login in Safe mode.
Take ownership of the folder.
Grant full control to your current account.
And try to delete.

It may take a few tries. You may have to take ownership of several folders and grant Full control access.

Or, even better if you will try the same method with Built-in Admin (http://www.sevenforums.com/tutorials/507-built-administrator-account-enable-disable.html)

Any chance, that reinstall is the choice? (Believe me it will be a lot less trouble)

And have you done this?
The System Volume Information stores system restore points and is undeletable.

If any or all restore points have an infection it may be best to turn of system restore and delete all restore points through Disk Cleanup - More options then when you are clean turn system restore back on and create a new restore point.

Hi Dinesh

Hitman Pro could not be run as it could not gain a internet connection. Dont know why as I am internet at same time and internet connection is good. Have noticed other malware and anti-virus programs can not access internet for updates. Could this be related??????? to problem with system volume information and $Recycle.bin.

In my opinion you have more then just this infection.
maybe you will post Hijack log?
 

My Computer My Computer

At a glance

Windows 7 Ultimate x86 SP1
OS
Windows 7 Ultimate x86 SP1
I have now tried renaming the folders and deleting them. I can rename them and when I do they disappear.

So it appears successful, however when you reopen the drive the folders reappear again with their original names.

There is obviously a hidden file or something that is controlling them and reinstalling the folders and files.


When I delete the $recycle.bin folder it mentiones desktop.ini files contained in the folder will be deleted as well. These are reinstated when the folder is reinstalled.

When I search programs and files I find one desktop.ini file with the following text

[LocalisedFileNames]
pinned .lnk=@c:\windows\system32\shell32.dll, -4161

Other copies of desktop.ini are hidden in folder and do not appear when I search.
View attachment hijackthis.log

View attachment AdAware Log 02-02-2010.txt
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
Hitman Pro could not be run as it could not gain a internet connection. Dont know why as I am internet at same time and internet connection is good. Have noticed other malware and anti-virus programs can not access internet for updates. Could this be related??????? to problem with system volume information and $Recycle.bin.
Those update sites for the security apps could be blocked by "Hosts" file entries.

Scroll down to "How do I reset the hosts file back to the default?"
Updating the HOSTS file in Windows 7 - Windows Forums

Also check Internet Options - Connections - Lan settings - untick use a proxy server and tick "Automatically detect settings"

Ya gonna have to get a scan down with an updated Malwarebytes and Hitman Pro as it will be too tedious trying to clean it up manually especially if it's an autorun worm.
 

My Computer My Computer

At a glance

7
OS
7

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks Jacee

I have the sal.xls.exe. I read the information about it and it is also called recycler virus.

I can see the System Volume Information folder and a $recycle.bin folder but not the Recycler folder.

I would like to know how to see all hidden files in Windows 7 so these appear with the file inside them.

I found the ctfmon.exe file but cant delete it as "I need permission from TrustedInstaller". This is a new user that has been created and I cant delete the files.

Any idea on how to delete them?
 

My Computer My Computer

At a glance

Windows 7Intel Cor TM i7 Q820 1.73gHz4.00GBNVIDIA GeForce 230M
Computer Manufacturer/Model Number
Hewlette-Packard
OS
Windows 7
CPU
Intel Cor TM i7 Q820 1.73gHz
Memory
4.00GB
Graphics Card(s)
NVIDIA GeForce 230M
Monitor(s) Displays
Generic PnP Monitor
Hard Drives
ST9500420AS * 2
Because "Virut" was shown by Sophos, this is a nasty Trojan ------

You're not only dealing with Virut but you are also dealing with a lot of other malware as well.
What I suggest in your case is to format and reinstall Windows. This because, Virut is a file infector which infects every .exe present on your system. The problem with Virut is, this is a buggy file infector and that's why scanners cannot disinfect them properly either > result > files are corrupted, won't work anymore.
And as I already explained, Virut infects every .exe.

This means that you may not delete these files, but they should be disinfected. And since it's a buggy virus, the files cannot be properly disinfected.

This unfortunately means that this is a game over situation and there's nothing much you can do besides formatting and reinstalling Windows.
Don't backup your files either, because when you backup exe files, they are also infected. You can however backup pictures and documents.


Look at the instructions on this page HM2K.com Win32 Virtob/Virut removal

It's up to you how you decide to work with this infection.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top