Solved

Files Disappeared

Posted on 2013-11-29
5
469 Views
Last Modified: 2013-12-05
Good Morning...I had a client who had her Outlook files disappear.  Luckily she had everything backed up so I was able to retrieve it.  I thought it strange that most of her other folders had a modification date of 11/26 so I ran malware scans and my last 2 MBAM and SAS were clean.  She then contacted me that all her other files were missing as well as her printer no longer worked.

The most alarming scan was the one I got from Rkill everything else seemed PUP related.

Rkill 2.6.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 11/27/2013 11:37:18 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Active Proxy Server Detected

 * Proxy Disabled.
 * ProxyOverride value deleted.
 * ProxyServer value deleted.
 * AutoConfigURL value deleted.
 * Proxy settings were backed up to Registry file.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Backup Registry file created at:
 C:\Users\MaryAnn\Desktop\rkill\rkill-11-27-2013-11-37-22.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

  * HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!


Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * WinDefend => %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [Incorrect ServiceDLL]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost

Program finished at: 11/27/2013 11:39:07 AM
Execution time: 0 hours(s), 1 minute(s), and 48 seconds(s)

Attached are the other scans,  Adobe Reader has been updated.

Her internet security is MSE with MBAM Pro, configured to work together.  The only PUP I found listed in her programs was Browser SafeGuard.

I appreciate you taking a look and letting me know what, if anything, I need to do next.
Thank you,
Mags
AdwCleaner-S0-.txt
JRT.txt
mbam-log-2013-11-27--11-42-53-.txt
mbam-log-2013-11-27--12-46-29-.txt
RKreport-0--S-11272013-132524.txt
RKreport-0--D-11272013-132627.txt
RKreport-0--PR-11272013-132635.txt
checkup.txt
Rkill--2.txt
0
Comment
Question by:MagsMcKinley14
  • 3
  • 2
5 Comments
 
LVL 50

Expert Comment

by:jcimarron
ID: 39685751
MagsMcKinley14--
How is the PC running now?  The printer? Have you deleted the items quarantined by MBAM?
Did you delete the PUP(s)?
"She then contacted me that all her other files were missing "  Have the missing files been restored?
0
 

Author Comment

by:MagsMcKinley14
ID: 39686211
PC is running fine.  Printer is working...user error.  All PUP's were deleted.  It is very strange. Some files were deleted and other not.  Pictures look like they are in tact.  Restored Documents from Backup.  That is were the major discrepancy was.  PUP's don't usually cause this...any idea what may have happened?  What about the Proxy message in Rkill??  I've never seen that one before.
0
 
LVL 50

Accepted Solution

by:
jcimarron earned 500 total points
ID: 39686223
MagsMcKinley14--Glad to hear all is well.

Regrets that I cannot tell you what caused the problem.  You mentioned user error concerning the printer.  Perhaps another user error concerning the proxy?  
But the same " messages" concerning the proxy were reported here
https://forums.malwarebytes.org/index.php?showtopic=136624 
and here
http://www.bleepingcomputer.com/forums/t/496019/i-indeed-have-a-virus-combo-fix-find-and-refinds/
and here
http://www.techspot.com/community/topics/cant-download-anti-virus-software-for-some-reason.189076/page-2

by users that had malware.  These could be false positives or just a reporting of the situation by RKill and not indicative of errors, though I see the messages were not repeated in subsequent scans after clean up.
0
 

Author Closing Comment

by:MagsMcKinley14
ID: 39699570
Thanks...not sure how she could of made all those changes.  I will post again if I experience more issues.
Thanks,
Mags
0
 
LVL 50

Expert Comment

by:jcimarron
ID: 39699647
MagsMcKinley14--You are welcome.
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 7 Lock taskbar 8 35
What are all these files on my C drive? 5 37
Folder Redirection - Disable Offline Synching for PCs 4 28
see android hidden files 10 22
You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
An analysis of the phishing scam that has been affecting Google users, along with steps to take for protection, as well as what to do if you receive one of the emails.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now