Solved

Files Disappeared

Posted on 2013-11-29
5
477 Views
Last Modified: 2013-12-05
Good Morning...I had a client who had her Outlook files disappear.  Luckily she had everything backed up so I was able to retrieve it.  I thought it strange that most of her other folders had a modification date of 11/26 so I ran malware scans and my last 2 MBAM and SAS were clean.  She then contacted me that all her other files were missing as well as her printer no longer worked.

The most alarming scan was the one I got from Rkill everything else seemed PUP related.

Rkill 2.6.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 11/27/2013 11:37:18 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Active Proxy Server Detected

 * Proxy Disabled.
 * ProxyOverride value deleted.
 * ProxyServer value deleted.
 * AutoConfigURL value deleted.
 * Proxy settings were backed up to Registry file.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Backup Registry file created at:
 C:\Users\MaryAnn\Desktop\rkill\rkill-11-27-2013-11-37-22.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

  * HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!


Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * WinDefend => %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [Incorrect ServiceDLL]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost

Program finished at: 11/27/2013 11:39:07 AM
Execution time: 0 hours(s), 1 minute(s), and 48 seconds(s)

Attached are the other scans,  Adobe Reader has been updated.

Her internet security is MSE with MBAM Pro, configured to work together.  The only PUP I found listed in her programs was Browser SafeGuard.

I appreciate you taking a look and letting me know what, if anything, I need to do next.
Thank you,
Mags
AdwCleaner-S0-.txt
JRT.txt
mbam-log-2013-11-27--11-42-53-.txt
mbam-log-2013-11-27--12-46-29-.txt
RKreport-0--S-11272013-132524.txt
RKreport-0--D-11272013-132627.txt
RKreport-0--PR-11272013-132635.txt
checkup.txt
Rkill--2.txt
0
Comment
Question by:MagsMcKinley14
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 50

Expert Comment

by:jcimarron
ID: 39685751
MagsMcKinley14--
How is the PC running now?  The printer? Have you deleted the items quarantined by MBAM?
Did you delete the PUP(s)?
"She then contacted me that all her other files were missing "  Have the missing files been restored?
0
 

Author Comment

by:MagsMcKinley14
ID: 39686211
PC is running fine.  Printer is working...user error.  All PUP's were deleted.  It is very strange. Some files were deleted and other not.  Pictures look like they are in tact.  Restored Documents from Backup.  That is were the major discrepancy was.  PUP's don't usually cause this...any idea what may have happened?  What about the Proxy message in Rkill??  I've never seen that one before.
0
 
LVL 50

Accepted Solution

by:
jcimarron earned 500 total points
ID: 39686223
MagsMcKinley14--Glad to hear all is well.

Regrets that I cannot tell you what caused the problem.  You mentioned user error concerning the printer.  Perhaps another user error concerning the proxy?  
But the same " messages" concerning the proxy were reported here
https://forums.malwarebytes.org/index.php?showtopic=136624 
and here
http://www.bleepingcomputer.com/forums/t/496019/i-indeed-have-a-virus-combo-fix-find-and-refinds/
and here
http://www.techspot.com/community/topics/cant-download-anti-virus-software-for-some-reason.189076/page-2

by users that had malware.  These could be false positives or just a reporting of the situation by RKill and not indicative of errors, though I see the messages were not repeated in subsequent scans after clean up.
0
 

Author Closing Comment

by:MagsMcKinley14
ID: 39699570
Thanks...not sure how she could of made all those changes.  I will post again if I experience more issues.
Thanks,
Mags
0
 
LVL 50

Expert Comment

by:jcimarron
ID: 39699647
MagsMcKinley14--You are welcome.
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Many of my clients call in with monstrous Gmail overloading issues with Outlook. A quick tip is to turn off the All Mail and Important folders from synching. Here is a quick video I made to show you how to turn off these and other folders in Gmail s…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question