Start a Conversation


This post is more than 5 years old


October 9th, 2011 09:00

trojan detected in empty recycle bin with kaspersky.

Inspiron 530/homeprium vista 32


Kaspersky anti-virus 2011 detected trojan.  No respond from Kaspersky when I clicked fix it or neutralized all. Right clicking the file and selecting the option to take me to the location of infected file says file does not exist. Updated malwarebytes came up empty. Tried to follow the path to the location of infected file shown on kaspersky but failed.

I remember deleting this infected file a few weeks ago when it was in Temp folder.  I also emptied the recycle bin at that time as well.  Back then, Kaspersky did not fix it automatically for me either that's why I did it myself.   The location of the file shown on kaspersky is c:\$recycle.bin\s-1-5-21-377169241-4253034272-93569241-1002\$ illustrator cs4 portable/adobeillustratorCS4portable.exe  Any suggestion? thanks.

27 Posts

October 9th, 2011 09:00

Update: I was able to follow the path to infected folder by logging into the user where the infected file is. i want to add a snapshot of the screen but I can't find that option.  Anyway, in the folder $recycle.bin there is a picture of the recycle bin follows by the file s-1-5.21-...... right cliking on the mouse gives me 2 options. to delete or empty recycle bin.  Which should I select.  

20.5K Posts

October 9th, 2011 12:00

Let us know if this answers your question or if there is anything else we can help you with.

20.5K Posts

October 9th, 2011 12:00

Hi Hualong,

First, are you sure that was not a false positive? Have you ever used adobeillustratorCS4portable.exe? If you downloaded it from a torrent site, yes, it is probably infected. Therefore, you could delete the file or empty the RB. Either way should get rid of it. Following that run Kaspersky again to see if it finds anything else. It would not hurt to do an online scan as well. It would be good to disable Kaspersky during the online scan so that the two scanners do not conflict. Give ESET a try here:
This scan works best with IE. Alternate browsers require downloading and installing the ESET Smart Installer.
•    Accept the Terms of Use:
•    Approve the install of the required ActiveX Control, then follow on-screen instructions. 
*  Disable the protection of your resident anti-virus program after installing the
active X control that Eset has installed and again when you actually start scanning.
•    Make sure enable (check) the Remove found threats option is checked, and run the scan.
•    After the scan completes, the Details tab in the Results window will display what was found and removed. A record of these results will be found here: C:\program files\esetonlinescanner\log.txt.
This online scan may take quite a bit of time to complete so please be patient. If necessary, allow the scan to run overnight. Please do not use the machine to do anything else (e.g. browse; check email; chat) until the scan completes.

** ESET Online Scanner works in Windows Vista and Windows 7, provided you
first start Internet Explorer as an Administrator. To do so,
right-click on the Internet Explorer icon in the Start Menu and select
"Run as administrator" from the popup context menu.

27 Posts

October 11th, 2011 13:00

I don't know how to tell if it's a false or real threat.  I will try what you have suggested and let you know.  Thanks for your suggestion.  Emptying the bin didn't work and I think if i select delete, it will delete my recycle bin from my computer.

20.5K Posts

October 11th, 2011 14:00

I thought you meant that there was an option in the RB to delete the file. I cannot run any diagnostics on this forum, so I cannot see where the file is. If you still need help after following the suggestions above, please post at SpywareHammer.

27 Posts

October 14th, 2011 09:00

Ran eset. 3 threats found...said something like variant of win32.  Threat were removed by eset but still have problem with this recycle bin.

20.5K Posts

October 14th, 2011 10:00

Please follow the instructions to post at SpywareHammer. They will help you with your problem and address any vulnerabilities that show up in your logs. You will need to register there before posting, but the help is free.

159 Posts

December 2nd, 2011 13:00

I think this virus is in your system volume information or system restore folders. Check them with your antivirus and also follow the instructions to post at SpywareHammer.

No Events found!
