cant even run read me!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mneenee, Oct 14, 2008.

  1. mneenee

    mneenee Corporal

    Hi this is my sisters laptop running windows xp home. It started when I borrowed hers to fix mine uhg. I started it up and when i did it wanted to do check disk. I didnt bother as she told me she didnt shut it down properly because it hasn't been letting her. then as it was starting to load the user screen, it said it couldnt load the local profileit as it couldnt find it. so when it started up it redid the desktop etc(like a new install of windows). then when starting internet explorer it started it like it was new? wasnt sure if she had just added it so I set it up and went on with what I was doing. when turning off IE (after downloading a few programs I needed)then restarted IE it did it again. Thats when I knew something was wrong. so I resarted the computer to see if it would do the same thing again. it did and when returning to the desktop for my downloads they were gone IE the same as before. So I checked her documents and they are all gone pictures too. I started the read me but when having to restart everything was lost from the desktop, however the mgtools is still there as well as the sas under program files. What should I do??? Is it gonna be possible to recover her files?

    Thanks
    Mneenee
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like a user profile was corrupt.....we need you to attach the logs that you do have (SAS and MGLogs.zip)and try to also run Malwarebytes and get us that log.
     
  3. mneenee

    mneenee Corporal

    Hi Tim, first of all thanks for your help. I am going to start over as the logs are gone. They disapear if the computer is restarted which it has been since my first post. I am not going to try to run spybot as it wants to restart. So I will try sas, mbam and mgtools. I probably shouldn't do combo fix as it restarts as well. so will do these couple of things and post logs.

    Thanks

    Mneenee
     
  4. mneenee

    mneenee Corporal

    Here are the logs, however they did not find anything as I believe it was all cleaned before. I have not restarted the computer do you think I should? Files and pics are all still missing.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First question before I look at your logs is have you checked each of these profiles:
    Code:
    C:\Documents and Settings\"
    DEFAUL~1      Aug 17 2004              "Default User"
    ALLUSE~1      Aug 17 2004              "All Users"
    USER          Aug 17 2004              "user"
    ADMINI~1      Jun 10 2005              "Administrator"
    TEMP          Oct 14 2008              "TEMP"
    USER~1.GAR    Oct 14 2008              "user.GARY"
    TEMP~1.GAR    Oct 14 2008              "TEMP.GARY"
    
     
  6. mneenee

    mneenee Corporal

    ok i found a bunch of files and pics under "user" not sure if it is everything though. Also found the combo fix log from when i did it earlier will attach it now.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.....I would suggest that you post in the software forum in order to sort out your user profiles and recover you pictures, etc. :)

    Let's just clean up some form the scans:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then:
     
  8. mneenee

    mneenee Corporal

    Okay did the reg thing and all went well but when uninstalling combofix through run it gives an error that says: Windows cannot find "C:\Documents and Settings\user.Gary\Desktop\combofix'. Make sure you typed the name correctly etc etc.

    This is probably because I am not using Gary right? should I still go to software?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....not sure which profile you downloaded it under....but you can manually remove it:
    you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.

    Then off to software and hopefully they can get your profiles straightened out. :)
     
  10. mneenee

    mneenee Corporal

    Okay Thank you so much for your help Tim it is greatly appreciated!!!!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....hope they can help you out. :)
     
  12. mneenee

    mneenee Corporal

    Hey Tim just wondering how long it takes to get a response from software forum. I still haven't had a reply since you sent me there on the 17th? And I don't want to bump:) Thanks

    Mneenee
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bump!!! Not a problem in software.....:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds