Programs disappeared! Not deleted...

Programs disappeared! Not deleted...

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Programs disappeared! Not deleted... Wolfie 08-27-2005
Posted by =?Utf-8?B?V29sZmll?= on August 27, 2005, 6:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Aug 24th, discovered my Outlook, Word, Excel, etc, as well as Morrowind,
Halo2 savegames, and many other programs, shortcuts, ini files, etc are just
Gone! The shortcuts pinned to the start menu for them are still there, but
say invalid shortcut. Less than a week earlier, I had installed the
Plug-n-Play vulnerability patch. I'm running XP Home.

I checked the recycle bin, not there. Checked the .exe files normal
locations, nada. Installed Iolo Search and Recover, they weren't found as
deleted. Oddly though, their remnants are there as deleted, looks like the
files were renamed "A<some number>.<original extension>", but their contents
are scrambled with control characters (for example, should be able to read a
.cfg or .ini file in Notepad, but can't cuz it's scrambled.) Registry still
has entries for the correct file names and the locations they Should have
been though. System Restore goes back no further than the 24th of Aug. It
is as if they were remotely uninstalled or something, renamed, scrambled, and
restore made impossible. All are programs that I own the license to use.

I use firewall (Windows) and through my ISP also (Cox), also do virus scans,
anti-spy/ad ware scans regularly. Did these scans but found no problems.
Got a Ton of processes running though, not sure which ones shouldn't be on my
computer... I backed up much of my drive bout a month ago, so gonna recopy
the main files, but seems like it could happen again.

Anyway, have you heard of this symptom ? Could it be a new virus? (Going
to use your recommended Multi-AV in the meantime)

Posted by David H. Lipman on August 27, 2005, 7:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| On Aug 24th, discovered my Outlook, Word, Excel, etc, as well as Morrowind,
| Halo2 savegames, and many other programs, shortcuts, ini files, etc are just
| Gone! The shortcuts pinned to the start menu for them are still there, but
| say invalid shortcut. Less than a week earlier, I had installed the
| Plug-n-Play vulnerability patch. I'm running XP Home.
|
| I checked the recycle bin, not there. Checked the .exe files normal
| locations, nada. Installed Iolo Search and Recover, they weren't found as
| deleted. Oddly though, their remnants are there as deleted, looks like the
| files were renamed "A<some number>.<original extension>", but their contents
| are scrambled with control characters (for example, should be able to read a
| .cfg or .ini file in Notepad, but can't cuz it's scrambled.) Registry still
| has entries for the correct file names and the locations they Should have
| been though. System Restore goes back no further than the 24th of Aug. It
| is as if they were remotely uninstalled or something, renamed, scrambled, and
| restore made impossible. All are programs that I own the license to use.
|
| I use firewall (Windows) and through my ISP also (Cox), also do virus scans,
| anti-spy/ad ware scans regularly. Did these scans but found no problems.
| Got a Ton of processes running though, not sure which ones shouldn't be on my
| computer... I backed up much of my drive bout a month ago, so gonna recopy
| the main files, but seems like it could happen again.
|
| Anyway, have you heard of this symptom ? Could it be a new virus? (Going
| to use your recommended Multi-AV in the meantime)

The symptoms sound like a virus that deletes EXE files.

The AV scan by COX is only goos for incoming email which contain viruses. Their
scan won't
protect you from getting infectors when browsing the Internet or using media
(CDROM,
floppies, Flash RAM, etc.) that has infectors on it. For that you need to have
an anti
virus scanner that is kept up to date and performing "On Access" scanning.

We await the results of the scans performksed within the Multi AV scanning tool
that I
wrote.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?V29sZmll?= on August 28, 2005, 10:25 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Trend found nothing, Sophos didn't output the \AV-CLS\Sophos\ScanReport.txt
file it should have, so I don't know there... McAfee locked up during scan of
\system32\config, just after system.log. But it did detect some
'Adware-GameSpyArcade.LNK and 'Adware-BJCFD' potentially unwanted programs in
some of the "Axxxxxxx.xxx" files, and deleted them. GameSpy is affiliated
with Halo's online game. (Halo is also one of the programs that got
renamed-scrambled-deleted. I'm gonna try them in Safe mode next...

"David H. Lipman" wrote:

>
> | On Aug 24th, discovered my Outlook, Word, Excel, etc, as well as Morrowind,
> | Halo2 savegames, and many other programs, shortcuts, ini files, etc are just
> | Gone! The shortcuts pinned to the start menu for them are still there, but
> | say invalid shortcut. Less than a week earlier, I had installed the
> | Plug-n-Play vulnerability patch. I'm running XP Home.
> |
> | I checked the recycle bin, not there. Checked the .exe files normal
> | locations, nada. Installed Iolo Search and Recover, they weren't found as
> | deleted. Oddly though, their remnants are there as deleted, looks like the
> | files were renamed "A<some number>.<original extension>", but their contents
> | are scrambled with control characters (for example, should be able to read a
> | .cfg or .ini file in Notepad, but can't cuz it's scrambled.) Registry still
> | has entries for the correct file names and the locations they Should have
> | been though. System Restore goes back no further than the 24th of Aug. It
> | is as if they were remotely uninstalled or something, renamed, scrambled, and
> | restore made impossible. All are programs that I own the license to use.
> |
> | I use firewall (Windows) and through my ISP also (Cox), also do virus scans,
> | anti-spy/ad ware scans regularly. Did these scans but found no problems.
> | Got a Ton of processes running though, not sure which ones shouldn't be on my
> | computer... I backed up much of my drive bout a month ago, so gonna recopy
> | the main files, but seems like it could happen again.
> |
> | Anyway, have you heard of this symptom ? Could it be a new virus? (Going
> | to use your recommended Multi-AV in the meantime)
>
> The symptoms sound like a virus that deletes EXE files.
>
> The AV scan by COX is only goos for incoming email which contain viruses.
Their scan won't
> protect you from getting infectors when browsing the Internet or using media
(CDROM,
> floppies, Flash RAM, etc.) that has infectors on it. For that you need to
have an anti
> virus scanner that is kept up to date and performing "On Access" scanning.
>
> We await the results of the scans performksed within the Multi AV scanning
tool that I
> wrote.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on August 28, 2005, 11:12 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Trend found nothing, Sophos didn't output the \AV-CLS\Sophos\ScanReport.txt
| file it should have, so I don't know there... McAfee locked up during scan of
| \system32\config, just after system.log. But it did detect some
| 'Adware-GameSpyArcade.LNK and 'Adware-BJCFD' potentially unwanted programs in
| some of the "Axxxxxxx.xxx" files, and deleted them. GameSpy is affiliated
| with Halo's online game. (Halo is also one of the programs that got
| renamed-scrambled-deleted. I'm gonna try them in Safe mode next...

Since non-viral malware was found, the following is also suggested....

Please download, install and update the following software...

Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
File disappeared May 21, 2007, 6:01 pm
Strange behaviour - some text and e-mails disappeared March 21, 2007, 5:03 pm
Mcafee cls deleted my dvd2one123.exe :-( October 1, 2006, 11:55 am
Mcafee cls deleted my dvd2one123.exe :-( October 1, 2006, 12:00 pm
Hosts file gets deleted automatically. July 16, 2007, 4:59 am
Microsoft AntiSpyware Recover deleted files August 5, 2005, 2:51 pm
temp folder files deleted on shutdown June 7, 2007, 5:13 am
Restoring files deleted by Windows Malicious Software Removal Tool May 17, 2006, 6:01 am
Some Programs (especially setup) Won't Run April 24, 2006, 4:15 pm
I have several spyware programs that I use but now I cannot do upd October 9, 2006, 10:47 pm

The site map in XML format XML site map

Contact Us | Privacy Policy