not all documents, pics showing

Discussion in 'Malware Help (A Specialist Will Reply)' started by dkkjhowe, Feb 14, 2015.

  1. dkkjhowe

    dkkjhowe Private E-2

    User could not see documents or pics, then noticed they had moved to user folder. Tried to copy/move back to documents, but was asked if they wanted to replace the current folder. So data just seems hidden.

    On advice of a co-worker, user ran ccleaner, superantispyware, malwarebytes, dr web, combofix, hijack this. Nothing worked. Then he tried a system restore. That restored but did not fix the problem.

    Called me. I live nearby and work on computers on the side but this is beyond me.

    I tried the UNHIDE, but since ccleaner had been run, that did not work. I notice there is also a program hanging out called reimage.

    Was afraid to run any further scans (per the read this first) or do anything other than clone the hard drive as a backup. Any thoughts as to how I should proceed?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. dkkjhowe

    dkkjhowe Private E-2

    Thanks for responding so quickly. I will begin the process immediately.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I doubt this is malware, but we will be able to tell once you attach the requested logs.
     
  5. dkkjhowe

    dkkjhowe Private E-2

    Thanks for your quick reply. I don't think it's malware either, but it's a place to start. Per your instructions, I have attached the logs from the scans I ran.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hitman is showing a lot of junk.....rerun it and have it remove all that it finds.

    Reboot and rescan with Hitman and attach the new log.

    Then:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  7. dkkjhowe

    dkkjhowe Private E-2

    Sorry for the delay. Had to be away. Here are the logs you asked for after running your latest instructions. Thanks again for your help.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All of the pictures are in this folder:
    C:\TEMP\documents and desktop\

    You may need to post in the software forum for help restoring them to their proper place.

    In the meantime:

    Use windows explorer to find and delete:
    C:\Windows\system32\tasks\ReimageUpdater
    C:\Program Files (x86)\AskPartnerNetwork
    C:\Program Files (x86)\McAfee Security Scan

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    I am not seeing any other issues with malware. How are things running?
     
  9. dkkjhowe

    dkkjhowe Private E-2

    Followed the directions as requested. Did not have a file for reimage in windows/system32/tasks. Did not have askpartnernetwork in program files.

    Ran the reg fix and got a successful message.

    I did know about the temp in c drive with docs and desktop. Everything I was able to see (docs and pics), I copied into that file and put it on a external hard drive separately for safekeeping. Sorry, forgot about that.

    Can create new folder now in documents. The document files that were not showing before are now there, but empty.

    I don't know how it happened but it appears everything in the documents, pictures, and desktop that related to documents or pictures disappeared from their folders. Many went into the main user file and others were here, there, and everywhere.

    If there is no malware, that is great. The user will have to re-file everything into the respective folders.

    Thanks so much for all your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds