Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

All files on the desktop have disappeared!


  • Please log in to reply
26 replies to this topic

#1 tureutter

tureutter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 04:56 PM

Hi! I really need some help here. Would appreciate it so much, because I've lost many important files and picture from my computer.

One day I was on the internet as usual. Just before that, my desktop was full of files and pictures that I had saved for years. But when I closed down my firefox and got to see the desktop again I discovered that all the saved files where gone! Folders were still there, just like I had saved them. But all the photos inside the folders had also disappeared!

So now I just have empty folders on my desktop and two shortcut files, to firefox and Picasa3. It seems like the shortcut files and the folders stayed, but all the others files & photos disappeared.

Another strange thing is that on my hard drive, no files have been removed or disappeared. The downloaded files that I had saved on my hardrive is still there.

I tried to save a file on the desktop one hour ago, and at first it seemed like that was OK, but after a while the file disappeared. So it seems like I can't save anything on the desktop at this time.

I've tried the explorer.exe thing. There's nothing "hidden", I've tried to cllick on "show hidden files". Nothing happens. I've tried a system retore, nothing there either.

I have XP Professional.

Can I in some way get my files and photos back? Appreciate all help. Thanks.

Edit: Moved topic from Windows XP Home and Professional to the more appropriate forum
by Roger

Edited by rotor123, 24 August 2012 - 05:47 PM.


BC AdBot (Login to Remove)

 


#2 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 05:49 PM

Have a look here download and run unhide.
http://www.bleepingcomputer.com/forums/topic405109.html

#3 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 06:17 PM

Have a look here download and run unhide.
http://www.bleepingcomputer.com/forums/topic405109.html


Tried. Got this;

Program started at: 08/25/2012 12:58:35 AM
Windows Version: Windows XP

Please be patient while your files are made visible again.

Processing the A:\ drive
Finished processing the A:\ drive. 0 files processed.

Processing the C:\ drive
Finished processing the C:\ drive. 65326 files processed.

Processing the F:\ drive
Finished processing the F:\ drive. 122 files processed.

The C:\DOCUME~1\dator1\LOCALS~1\Temp\smtmp\ folder does not exist!!
Unhide cannot restore your missing shortcuts!!
Please see this topic in order to learn how to restore default
Start Menu shortcuts: http://www.bleepingcomputer.com/forums/topic405109.html

Searching for Windows Registry changes made by FakeHDD rogues.
- Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
No registry changes detected.

Restarting Explorer.exe in order to apply changes.

Program finished at: 08/25/2012 01:07:38 AM
Execution time: 0 hours(s), 9 minute(s), and 3 seconds(s)

#4 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 06:26 PM

Please download FarbarServiceScanner and run it on the computer with the issue.


Make sure the following options are checked:
Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update

Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Please ATTACH the log to your reply.

Please download MINITOOLBOX and run it.

Checkmark following boxes:


Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List Devices (problems only)



Click Go and Attach the result.

Download Ad-ware Cleaner Click the delete button allow it to run and post the log it creates.

http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner


Now download the program below run it then hit the fix hosts button then the fix dns then hit the scan button let it finish then hit the delete button.

http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe

#5 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 06:57 PM

Farbar;
Farbar Service Scanner Version: 06-08-2012
Ran by dator1 (administrator) on 25-08-2012 at 01:49:50
Running from "C:\Documents and Settings\dator1\My Documents\Hämtade filer"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
Avgfwfd(9) Avgtdix(8) Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3)
0x09000000040000000100000002000000030000000900000008000000050000000600000007000000
IpSec Tag value is correct.

**** End of log ****


Minitoolbox
MiniToolBox by Farbar Version: 23-07-2012
Ran by dator1 (administrator) on 25-08-2012 at 01:51:36
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

"network.proxy.type", 0
========================= Hosts content: =================================


127.0.0.1 localhost
127.0.0.1 mpa.one.microsoft.com

========================= IP Configuration: ================================

Realtek RTL8139 Family PCI Fast Ethernet NIC = Local Area Connection (Connected)


# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Local Area Connection"

set address name="Local Area Connection" source=dhcp
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : computer_1

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast Ethernet NIC

Physical Address. . . . . . . . . : 00-15-F2-74-DE-91

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.0.3

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.0.1

DHCP Server . . . . . . . . . . . : 192.168.0.1

DNS Servers . . . . . . . . . . . : 85.30.160.10

85.30.129.10

Lease Obtained. . . . . . . . . . : den 25 augusti 2012 01:46:48

Lease Expires . . . . . . . . . . : den 28 augusti 2012 01:46:48

Server: ns2.teleservice.net
Address: 85.30.160.10

Name: google.com
Addresses: 173.194.32.35, 173.194.32.36, 173.194.32.37, 173.194.32.38
173.194.32.39, 173.194.32.40, 173.194.32.41, 173.194.32.46, 173.194.32.32
173.194.32.33, 173.194.32.34



Pinging google.com [173.194.32.35] with 32 bytes of data:



Reply from 173.194.32.35: bytes=32 time=22ms TTL=51

Reply from 173.194.32.35: bytes=32 time=18ms TTL=51



Ping statistics for 173.194.32.35:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 18ms, Maximum = 22ms, Average = 20ms

Server: ns2.teleservice.net
Address: 85.30.160.10

Name: yahoo.com
Addresses: 98.138.253.109, 98.139.183.24, 72.30.38.140



Pinging yahoo.com [98.139.183.24] with 32 bytes of data:



Reply from 98.139.183.24: bytes=32 time=137ms TTL=45

Reply from 98.139.183.24: bytes=32 time=144ms TTL=45



Ping statistics for 98.139.183.24:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 137ms, Maximum = 144ms, Average = 140ms

Server: ns2.teleservice.net
Address: 85.30.160.10

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



Request timed out.

Request timed out.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 15 f2 74 de 91 ...... Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.3 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.0.0 255.255.255.0 192.168.0.3 192.168.0.3 20
192.168.0.3 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.0.255 255.255.255.255 192.168.0.3 192.168.0.3 20
224.0.0.0 240.0.0.0 192.168.0.3 192.168.0.3 20
255.255.255.255 255.255.255.255 192.168.0.3 192.168.0.3 1
Default Gateway: 192.168.0.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (08/24/2012 10:34:20 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System detected an inconsistency in its internal state. The assertion "GetLastError() == 122L" failed at line 162 of d:\comxp_sp3\com\com1x\src\events\shared\sectools.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (08/23/2012 05:28:33 PM) (Source: ESENT) (User: )
Description: svchost (1320) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).

Error: (08/17/2012 09:17:27 PM) (Source: Application Error) (User: )
Description: Faulting application skype.exe, version 5.10.0.116, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x0000984e.
Processing media-specific event for [skype.exe!ws!]

Error: (08/15/2012 04:46:04 PM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (08/07/2012 03:28:39 AM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (08/07/2012 03:28:39 AM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (08/07/2012 03:28:37 AM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (08/07/2012 03:28:33 AM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (07/02/2012 01:14:25 PM) (Source: Application Error) (User: )
Description: Faulting application skype.exe, version 5.9.0.123, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x0000984e.
Processing media-specific event for [skype.exe!ws!]

Error: (07/02/2012 01:11:18 PM) (Source: Application Hang) (User: )
Description: Hanging application firefox.exe, version 12.0.0.4493, hang module hungapp, version 0.0.0.0, hang address 0x00000000.


System errors:
=============
Error: (08/24/2012 10:39:50 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (08/24/2012 10:38:38 PM) (Source: DCOM) (User: COMPUTER_1)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (08/24/2012 10:38:28 PM) (Source: DCOM) (User: COMPUTER_1)
Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error: (08/24/2012 10:38:00 PM) (Source: DCOM) (User: COMPUTER_1)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (08/24/2012 10:37:33 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
AFD
Avgldx86
Avgmfx86
Avgtdix
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
SCDEmu
Tcpip

Error: (08/24/2012 10:37:33 PM) (Source: Service Control Manager) (User: )
Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31

Error: (08/24/2012 10:37:33 PM) (Source: Service Control Manager) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31

Error: (08/24/2012 10:37:33 PM) (Source: Service Control Manager) (User: )
Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31

Error: (08/24/2012 10:37:33 PM) (Source: Service Control Manager) (User: )
Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
%%31

Error: (08/24/2012 10:37:07 PM) (Source: DCOM) (User: COMPUTER_1)
Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}


Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

Adobe Flash Player 11 Plugin (Version: 11.3.300.271)
Adobe Reader X (10.1.3) - Svenska (Version: 10.1.3)
ATI Catalyst Control Center (Version: 1.2.2153.2409)
ATI Display Driver (Version: 8.201-051122a1-029288C-NEC CI)
AVG 2012 (Version: 12.0.2197)
AVG 2012 (Version: 12.0.2437)
AVG 2012 (Version: 2012.0.2197)
BitComet 1.32 (Version: 1.32)
Free YouTube Downloader 3.5.126
ImgBurn (Version: 2.5.7.0)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft IntelliType Pro 8.2 (Version: 8.20.469.0)
Microsoft Office Access MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014)
Microsoft Office Excel MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Groove MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office InfoPath MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office OneNote MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Outlook MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office PowerPoint MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (Finnish) 2007 (Version: 12.0.4518.1017)
Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Proofing (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Publisher MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Shared MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Office Word MUI (Swedish) 2007 (Version: 12.0.4518.1018)
Microsoft Software Update for Web Folders (Swedish) 12 (Version: 12.0.4518.1018)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
mkv2vob (Version: 2.4.9)
Mozilla Firefox 12.0 (x86 sv-SE) (Version: 12.0)
Mozilla Maintenance Service (Version: 12.0)
Picasa 3 (Version: 3.8)
PowerISO (Version: 5.1)
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0)
RealPlayer (Version: 15.0.4)
Realtek AC'97 Audio (Version: 5.36)
RealUpgrade 1.1 (Version: 1.1.0)
Skype Click to Call (Version: 6.1.10441)
Skype™ 5.10 (Version: 5.10.116)
SopCast 3.5.0 (Version: 3.5.0)
Spotify (Version: 0.8.4.107.g4fa0003f)
Update for Windows Internet Explorer 8 (KB2598845) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2467659) (Version: 1)
Update for Windows XP (KB2641690) (Version: 1)
Update for Windows XP (KB2718704) (Version: 1)
Update for Windows XP (KB898461) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
WebFldrs XP (Version: 9.50.7523)
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (Version: 1.0)
Windows Internet Explorer 8 (Version: 20090308.140743)
WinRAR 4.20 beta 2 (32-bit) (Version: 4.20.2)
VLC media player 2.0.1 (Version: 2.0.1)
YouTube to MP3 Converter (Version: 1.3.0.404)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 34%
Total physical RAM: 2046.73 MB
Available physical RAM: 1343.59 MB
Total Pagefile: 3939.74 MB
Available Pagefile: 3291.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.98 MB

========================= Partitions: =====================================

2 Drive c: () (Fixed) (Total:186.3 GB) (Free:155.01 GB) NTFS

========================= Users: ========================================

User accounts for \\COMPUTER_1

Administrator ASPNET dator1
Guest HelpAssistant SUPPORT_388945a0


**** End of log ****



Ad ware cleaner:

# AdwCleaner v1.801 - Logfile created 08/25/2012 at 01:44:35
# Updated 14/08/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : dator1 - COMPUTER_1
# Boot Mode : Normal
# Running from : C:\Documents and Settings\dator1\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Registre - GUID] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (sv-SE)

Profile name : default
File : C:\Documents and Settings\dator1\Application Data\Mozilla\Firefox\Profiles\0oteer7h.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [765 octets] - [25/08/2012 01:44:35]

########## EOF - C:\AdwCleaner[S1].txt - [892 octets] ##########

Roguekiller
RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: dator1 [Admin rights]
Mode: Remove -- Date: 08/25/2012 01:55:40

¤¤¤ Bad processes: 5 ¤¤¤
[SUSP PATH] YouTubeDownloaderExtension.dll -- C:\Documents and Settings\dator1\Local Settings\Application Data\Sevas-S\YouTube to MP3 Converter\BrowserExtensions\IE\YouTubeDownloaderExtension.dll -> UNLOADED
[SUSP PATH] defender.exe -- C:\Documents and Settings\dator1\Local Settings\Application Data\Sevas-S\Defender\defender.exe -> KILLED [TermProc]
[SUSP PATH] updater.exe -- C:\Documents and Settings\dator1\Local Settings\Application Data\Sevas-S\Updater\updater.exe -> KILLED [TermProc]
[SUSP PATH] yt2mp3converter.exe -- C:\Documents and Settings\dator1\Local Settings\Application Data\Sevas-S\YouTube To MP3 Converter\yt2mp3converter.exe -> KILLED [TermProc]
[SUSP PATH] c2c_service.exe -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe -> KILLED [TermProc]

¤¤¤ Registry Entries: 3 ¤¤¤
[SUSP PATH] HKLM\[...]\Run : Sevas-SSoftwareDefender (C:\Documents and Settings\dator1\Local Settings\Application Data\Sevas-S\Defender\defender.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : Sevas-SSoftwareUpdater (C:\Documents and Settings\dator1\Local Settings\Application Data\Sevas-S\Updater\updater.exe) -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST3200826AS +++++
--- User ---
[MBR] e2b67d99f06a764d15d689de60c8da85
[BSP] 987cf5983f07a295a06cf311d092e291 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 190771 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[5].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt

Appreciate the help!

#6 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 07:17 PM

Uninstall AVG then run the removal tool then reboot.
http://majorgeeks.com/downloadget.php?id=7000&file=1&evp=90a64cb792b5baa6613cd88621e1213a

Install Avast free.
http://www.filehippo.com/download_avast_antivirus/

Download and run the windows all in one repair tool and run it with all the boxes checked except the ones below.
http://majorgeeks.com/Tweaking.com_-_Windows_Repair_d7141.html

Remove temp files

Repair proxy settings

Repair cd/dvd missing

Repair side bar gadgets


Repair snipping tool

Now after the tool runs then reboot and check your issue.

#7 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 08:27 PM

Still in progress. 10min.

#8 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 08:43 PM

:thumbup2:

#9 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 08:44 PM

Should I perform a full scan now? Or what do you mean with "check your issue"?

#10 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 08:59 PM

I meant after the all in one repair tool finishes and you reboot see if the files on your desktop have come back

#11 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 09:02 PM

Oh. No, they haven't. It seems to be impossible. Nothing there, just emtpy folders and shortcuts.

#12 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 09:11 PM

I don't know if this says something but I find all the desktop files in C:\Documents and Settings\computer1\Recent documents. But only as shortcuts, and I can't open a single file.

#13 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 09:13 PM

Rerun the rouge killer and hit the fix shortcuts then reboot and check issue.

If that fails the run a scan with eset online scanner
http://www.eset.com/us/online-scanner/

#14 InadequateInfirmity

InadequateInfirmity

    I Gots Me A Certified Edumication


  • Banned
  • 5,180 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 24 August 2012 - 09:16 PM

Also create a restore point and then go to the link below and run the .exe fix and the folder association fix.
http://www.dougknox.com/xp/file_assoc.htm

Reboot and check issue.

#15 tureutter

tureutter
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:12:05 PM

Posted 24 August 2012 - 09:31 PM

Performing scan now. Thanks for the help.

One quick question as the scan performs. I saved some files and photos on a usb stick, but then they got deleted and new things was put on the usb stick. You cant, in some way, restore the former files?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users