• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 491
  • Last Modified:

Files Disappeared

Good Morning...I had a client who had her Outlook files disappear.  Luckily she had everything backed up so I was able to retrieve it.  I thought it strange that most of her other folders had a modification date of 11/26 so I ran malware scans and my last 2 MBAM and SAS were clean.  She then contacted me that all her other files were missing as well as her printer no longer worked.

The most alarming scan was the one I got from Rkill everything else seemed PUP related.

Rkill 2.6.3 by Lawrence Abrams (Grinler)
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:

Program started at: 11/27/2013 11:37:18 AM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Active Proxy Server Detected

 * Proxy Disabled.
 * ProxyOverride value deleted.
 * ProxyServer value deleted.
 * AutoConfigURL value deleted.
 * Proxy settings were backed up to Registry file.

Checking Registry for malware related settings:

 * No issues found in the Registry.

Backup Registry file created at:

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
  * HKLM\Software\Classes\exefile\shell\open\command\\IsolatedCommand was changed. It was reset to "%1" %*!

  * HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * WinDefend => %ProgramFiles(x86)%\Windows Defender\mpsvc.dll [Incorrect ServiceDLL]

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:       localhost

Program finished at: 11/27/2013 11:39:07 AM
Execution time: 0 hours(s), 1 minute(s), and 48 seconds(s)

Attached are the other scans,  Adobe Reader has been updated.

Her internet security is MSE with MBAM Pro, configured to work together.  The only PUP I found listed in her programs was Browser SafeGuard.

I appreciate you taking a look and letting me know what, if anything, I need to do next.
Thank you,
  • 3
  • 2
1 Solution
How is the PC running now?  The printer? Have you deleted the items quarantined by MBAM?
Did you delete the PUP(s)?
"She then contacted me that all her other files were missing "  Have the missing files been restored?
MagsOwnerAuthor Commented:
PC is running fine.  Printer is working...user error.  All PUP's were deleted.  It is very strange. Some files were deleted and other not.  Pictures look like they are in tact.  Restored Documents from Backup.  That is were the major discrepancy was.  PUP's don't usually cause this...any idea what may have happened?  What about the Proxy message in Rkill??  I've never seen that one before.
MagsMcKinley14--Glad to hear all is well.

Regrets that I cannot tell you what caused the problem.  You mentioned user error concerning the printer.  Perhaps another user error concerning the proxy?  
But the same " messages" concerning the proxy were reported here
and here
and here

by users that had malware.  These could be false positives or just a reporting of the situation by RKill and not indicative of errors, though I see the messages were not repeated in subsequent scans after clean up.
MagsOwnerAuthor Commented:
Thanks...not sure how she could of made all those changes.  I will post again if I experience more issues.
MagsMcKinley14--You are welcome.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now