missing my document files for one user

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chrissykitty, Dec 28, 2005.

  1. chrissykitty

    chrissykitty Private E-2

    hideeeho,
    i need a little help, please. i have three user accounts on my computer, two are setup as admins and one of these accounts has come up missing all of the photos, music, etc... from her account. when she logged, in her desktop had reverted back to a blue screen and only default 'sample pictures' were in her my pictures file. i went through all of the steps in the spyware section and i have no known spyware or virus issues. i have attached sysinfo and a hijackthis log. maybe you can help.
    thanks!
     

    Attached Files:

  2. Adrynalyne

    Adrynalyne Guest

    Unless you have gone through this:
    http://forums.majorgeeks.com/showthread.php?t=35407

    Nobody is going to review the HJT log.

    The first step should be to list the names of all the folders located in C:\Documents and Settings.

    What is the name (not password) of the user account in question?
     
  3. chrissykitty

    chrissykitty Private E-2

    the username was goli. i did a system restore to two days ago and the desktop came back up but am missing a large picture file 'emma picmaster' which has all of my daughters' pictures in it. i have found some of the files using search option but this is the main one i am looking for and it does not come up using the search option. i ran all of the options in the sticky thread but after doing a system restore it would seem i need to rerun the options again.
     
  4. tigerray00

    tigerray00 Specialist

    What version of windows are you using? In windows 98 this happens when you log in with the wrong password sometimes
     
  5. Adrynalyne

    Adrynalyne Guest

    It can only be Windows ME or Windows XP. In this case its XP.
     
  6. chrissykitty

    chrissykitty Private E-2

    i am running xp professional media center version
     
  7. chrissykitty

    chrissykitty Private E-2

    if i continue to run the processes in the virus removal sticky thread will i decrease my chances of getting this folder back?
     
  8. Adrynalyne

    Adrynalyne Guest

    Can you go through my first post please :) List the folder names.

    List the names of the folders, because this sure does sound like a corrupt user profile.
     
  9. chrissykitty

    chrissykitty Private E-2

    it contained all of the regular folders under my documents, and inside the 'my pictures' file was emmas picmaster, ch, delly's picture to be burnt to cd, i seem to be only missing the large file emma's picmaster.
     
  10. Adrynalyne

    Adrynalyne Guest

    I'm not asking whats under my documents.

    I'm asking what folders are under C:\Documents and Settings.
     
  11. chrissykitty

    chrissykitty Private E-2

    this is the current contents of my documents and settings files;
     

    Attached Files:

  12. Adrynalyne

    Adrynalyne Guest

    *bangs head against wall*

    C:\Documents and Settings

    Not a subdirectory. :)
     
  13. chrissykitty

    chrissykitty Private E-2

    tryy this;
     

    Attached Files:

  14. Adrynalyne

    Adrynalyne Guest

    Can you undo your last restoration?
     
  15. chrissykitty

    chrissykitty Private E-2

    i have undone my last restorationand these are what has come up;
    the system 32\netsh.exe and the \z14.exe are unfamiliar to me.
     

    Attached Files:

  16. Adrynalyne

    Adrynalyne Guest

    Ok, make sure you follow the post I linked to at the top. I'll move this to the spyware forum.
     
  17. chrissykitty

    chrissykitty Private E-2

    if i follow the sticky thread will i lose the possibility of getting the misssing file back?
     
  18. chrissykitty

    chrissykitty Private E-2

    have to leave for work, will pick up thread when i return. thanks for all the help so far!!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the file was deleted/erased. Everything you have done thus far may have overwritten the contents on your hard disk. Even installing a program to undelete files (if that is the problem) could potentially overwrite the data you may need.

    Did you ever look in the Recycle Bin to see if it is in there? But if you ran Ccleaner and that is probably gone too.
     
  20. chrissykitty

    chrissykitty Private E-2

    i have not run ccleaner yet because that will definitely trash it, i think, but would the file restore overwrite the file?
    i found all of the files but the 'emmapicmaster' file in the recycle bin before. it is now empty. i have backed up all of the pics but am missing one month of pictures stuck in with this folder. would the size of the file have anything to do with the difficulty in finding or restoring it?
     
  21. chrissykitty

    chrissykitty Private E-2

    am really going to be late now, will pickup thread later, thanks.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you said you went thru all the steps! One of them was Ccleaner. So are you saying you did not run ALL the steps.

    If the folder is deleted and it is not in the Recycle Bin. You are not going to find it. You would need a program that shows deleted files and folders. But installing that (as I already said) could overwrite the area of the disk where you picture data was stored.


    The below two problem processes are running. The strange thing is I do not see where they are loading. Perhaps they loaded from another user account because it looks like you are logged in multiple times (at least you were when you posted the original HJT log).
    C:\WINDOWS\system32\cmd32.exe <---- cmd32.exe is added to the system as a result of the P2P.TANKED virus
    C:\WINDOWS\system32\z12.exe <--- this is probably a dialer
    Reboot you PC and only log into one account and attach a new HJT log for that account. Tell me which account it is too.
     
  23. chrissykitty

    chrissykitty Private E-2

    i am sorry about posting a new thread. yet again, this is probably the only forum i have ever used. at least i will not make the same mistake twice. i have gone over the sticky thread and have run hijackthis properly this time and it is attached. i have also gone through the special removal for smitfraud and i have logs from panda if you need them.
    if i have made another mistake this time, please let me know and i will promptly correct it.
    thanks for all your help.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HJT fix the below lines:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Yes attach the Panda log. Did you run BitDefender? Attach the log.

    Why did you run stuff for Smitfraud?

    Are you currently having any malware problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds