Solved

Files Disappeared

Posted on 2013-11-29
5
475 Views
Last Modified: 2013-12-05
Good Morning...I had a client who had her Outlook files disappear.  Luckily she had everything backed up so I was able to retrieve it.  I thought it strange that most of her other folders had a modification date of 11/26 so I ran malware scans and my last 2 MBAM and SAS were clean.  She then contacted me that all her other files were missing as well as her printer no longer worked.

The most alarming scan was the one I got from Rkill everything else seemed PUP related.

Rkill 2.6.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 11/27/2013 11:37:18 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Active Proxy Server Detected

 * Proxy Disabled.
 * ProxyOverride value deleted.
 * ProxyServer value deleted.
 * AutoConfigURL value deleted.
 * Proxy settings were backed up to Registry file.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Backup Registry file created at:
 C:\Users\MaryAnn\Desktop\rkill\rkill-11-27-2013-11-37-22.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

  * HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!


Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * WinDefend => %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [Incorrect ServiceDLL]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost

Program finished at: 11/27/2013 11:39:07 AM
Execution time: 0 hours(s), 1 minute(s), and 48 seconds(s)

Attached are the other scans,  Adobe Reader has been updated.

Her internet security is MSE with MBAM Pro, configured to work together.  The only PUP I found listed in her programs was Browser SafeGuard.

I appreciate you taking a look and letting me know what, if anything, I need to do next.
Thank you,
Mags
AdwCleaner-S0-.txt
JRT.txt
mbam-log-2013-11-27--11-42-53-.txt
mbam-log-2013-11-27--12-46-29-.txt
RKreport-0--S-11272013-132524.txt
RKreport-0--D-11272013-132627.txt
RKreport-0--PR-11272013-132635.txt
checkup.txt
Rkill--2.txt
0
Comment
Question by:MagsMcKinley14
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 50

Expert Comment

by:jcimarron
ID: 39685751
MagsMcKinley14--
How is the PC running now?  The printer? Have you deleted the items quarantined by MBAM?
Did you delete the PUP(s)?
"She then contacted me that all her other files were missing "  Have the missing files been restored?
0
 

Author Comment

by:MagsMcKinley14
ID: 39686211
PC is running fine.  Printer is working...user error.  All PUP's were deleted.  It is very strange. Some files were deleted and other not.  Pictures look like they are in tact.  Restored Documents from Backup.  That is were the major discrepancy was.  PUP's don't usually cause this...any idea what may have happened?  What about the Proxy message in Rkill??  I've never seen that one before.
0
 
LVL 50

Accepted Solution

by:
jcimarron earned 500 total points
ID: 39686223
MagsMcKinley14--Glad to hear all is well.

Regrets that I cannot tell you what caused the problem.  You mentioned user error concerning the printer.  Perhaps another user error concerning the proxy?  
But the same " messages" concerning the proxy were reported here
https://forums.malwarebytes.org/index.php?showtopic=136624 
and here
http://www.bleepingcomputer.com/forums/t/496019/i-indeed-have-a-virus-combo-fix-find-and-refinds/
and here
http://www.techspot.com/community/topics/cant-download-anti-virus-software-for-some-reason.189076/page-2

by users that had malware.  These could be false positives or just a reporting of the situation by RKill and not indicative of errors, though I see the messages were not repeated in subsequent scans after clean up.
0
 

Author Closing Comment

by:MagsMcKinley14
ID: 39699570
Thanks...not sure how she could of made all those changes.  I will post again if I experience more issues.
Thanks,
Mags
0
 
LVL 50

Expert Comment

by:jcimarron
ID: 39699647
MagsMcKinley14--You are welcome.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

697 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question