?
Solved

Files Disappeared

Posted on 2013-11-29
5
Medium Priority
?
487 Views
Last Modified: 2013-12-05
Good Morning...I had a client who had her Outlook files disappear.  Luckily she had everything backed up so I was able to retrieve it.  I thought it strange that most of her other folders had a modification date of 11/26 so I ran malware scans and my last 2 MBAM and SAS were clean.  She then contacted me that all her other files were missing as well as her printer no longer worked.

The most alarming scan was the one I got from Rkill everything else seemed PUP related.

Rkill 2.6.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 11/27/2013 11:37:18 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Active Proxy Server Detected

 * Proxy Disabled.
 * ProxyOverride value deleted.
 * ProxyServer value deleted.
 * AutoConfigURL value deleted.
 * Proxy settings were backed up to Registry file.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Backup Registry file created at:
 C:\Users\MaryAnn\Desktop\rkill\rkill-11-27-2013-11-37-22.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

  * HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!


Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * WinDefend => %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [Incorrect ServiceDLL]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost

Program finished at: 11/27/2013 11:39:07 AM
Execution time: 0 hours(s), 1 minute(s), and 48 seconds(s)

Attached are the other scans,  Adobe Reader has been updated.

Her internet security is MSE with MBAM Pro, configured to work together.  The only PUP I found listed in her programs was Browser SafeGuard.

I appreciate you taking a look and letting me know what, if anything, I need to do next.
Thank you,
Mags
AdwCleaner-S0-.txt
JRT.txt
mbam-log-2013-11-27--11-42-53-.txt
mbam-log-2013-11-27--12-46-29-.txt
RKreport-0--S-11272013-132524.txt
RKreport-0--D-11272013-132627.txt
RKreport-0--PR-11272013-132635.txt
checkup.txt
Rkill--2.txt
0
Comment
Question by:Mags
  • 3
  • 2
5 Comments
 
LVL 50

Expert Comment

by:jcimarron
ID: 39685751
MagsMcKinley14--
How is the PC running now?  The printer? Have you deleted the items quarantined by MBAM?
Did you delete the PUP(s)?
"She then contacted me that all her other files were missing "  Have the missing files been restored?
0
 

Author Comment

by:Mags
ID: 39686211
PC is running fine.  Printer is working...user error.  All PUP's were deleted.  It is very strange. Some files were deleted and other not.  Pictures look like they are in tact.  Restored Documents from Backup.  That is were the major discrepancy was.  PUP's don't usually cause this...any idea what may have happened?  What about the Proxy message in Rkill??  I've never seen that one before.
0
 
LVL 50

Accepted Solution

by:
jcimarron earned 2000 total points
ID: 39686223
MagsMcKinley14--Glad to hear all is well.

Regrets that I cannot tell you what caused the problem.  You mentioned user error concerning the printer.  Perhaps another user error concerning the proxy?  
But the same " messages" concerning the proxy were reported here
https://forums.malwarebytes.org/index.php?showtopic=136624 
and here
http://www.bleepingcomputer.com/forums/t/496019/i-indeed-have-a-virus-combo-fix-find-and-refinds/
and here
http://www.techspot.com/community/topics/cant-download-anti-virus-software-for-some-reason.189076/page-2

by users that had malware.  These could be false positives or just a reporting of the situation by RKill and not indicative of errors, though I see the messages were not repeated in subsequent scans after clean up.
0
 

Author Closing Comment

by:Mags
ID: 39699570
Thanks...not sure how she could of made all those changes.  I will post again if I experience more issues.
Thanks,
Mags
0
 
LVL 50

Expert Comment

by:jcimarron
ID: 39699647
MagsMcKinley14--You are welcome.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

IF you are either unfamiliar with rootkits, or want to know more about them, read on ....
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…
Suggested Courses

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question