FPCH Staff Tony D Posted February 24, 2017 FPCH Staff Posted February 24, 2017 User calls me today because his desktop and taskbar were missing some icons. Additionally, his documents are gone. Went over there and found when you open the user's account and click on the documents icon in the left-hand pane, indeed there were no documents. I checked Properties of the Documents library link it and it was pointing to C:\Users\\Temp. The documents were intact and in C:\Users\\Documents where you'd expect them. I redirected the link to the proper folder. When he opened Outlook, it looked as if it were opening for the first time. It wanted to set up his email account. I searched and couldn't find his pst file. I even searched with Show hidden files enabled. I added Word and PowerPoint back to his taskbar. Any idea of what happened? Maybe a disk hiccup. I should have ran chkdsk before I left. Quote
FPCH Admin allheart55 Cindy E Posted February 24, 2017 FPCH Admin Posted February 24, 2017 It might have helped if you ran Recuva or Everything on it. Quote ~I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.~ ~~Robert McCloskey~~
FPCH Staff Tony D Posted February 24, 2017 Author FPCH Staff Posted February 24, 2017 There was no need. The files were there. Well, except for that pst file. Thinking of it, maybe there are other files missing. Thanks for the suggestion. btw: I'm not familiar with Everything Quote
DSTM Posted February 25, 2017 Posted February 25, 2017 "Everything" is brilliant, Tony. I wouldn't be without it. Quote Roses are red, violets are blue, I'm Schizophrenic, and so am I Free Photo Restoration and Repair for all Forum members - CLICK HERE Please pop back and let us know if your Computer problem has been solved.
FPCH Staff Tony D Posted February 25, 2017 Author FPCH Staff Posted February 25, 2017 I searched the User directory for *.pst. It found some contact pst file that hadn't been modified for a few years. So that wasn't the right pst file. It seems to me that search would have worked. I may return next week and try the Everything app to see what it does. Quote
FPCH Admin allheart55 Cindy E Posted February 25, 2017 FPCH Admin Posted February 25, 2017 The search everything app works really well. I have it on every computer. Dougie turned me on to it about five years ago. There's even a portable version now. 1 Quote ~I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.~ ~~Robert McCloskey~~
plodr Posted February 25, 2017 Posted February 25, 2017 I use Search Everything but I've now also added Agent Ransack too. https://www.mythicsoft.com/agentransack Quote
FPCH Admin allheart55 Cindy E Posted February 25, 2017 FPCH Admin Posted February 25, 2017 That looks interesting, plodr. Quote ~I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.~ ~~Robert McCloskey~~
FPCH Staff Tony D Posted February 25, 2017 Author FPCH Staff Posted February 25, 2017 Anyone have an idea of why the documents shortcut target, desktop and taskbar got changed? That was my question. Quote
FPCH Admin allheart55 Cindy E Posted February 25, 2017 FPCH Admin Posted February 25, 2017 Have you checked for malware, Tony? Quote ~I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.~ ~~Robert McCloskey~~
FPCH Admin allheart55 Cindy E Posted February 25, 2017 FPCH Admin Posted February 25, 2017 Also....If there were bad sectors on the hard drive and items were moved...?? 1 Quote ~I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.~ ~~Robert McCloskey~~
starbuck Posted February 27, 2017 Posted February 27, 2017 when you open the user's account and click on the documents icon in the left-hand pane, indeed there were no documents. I checked Properties of the Documents library link it and it was pointing to C:\Users\<his user name>\Temp. The documents were intact and in C:\Users\<his user name>\Documents where you'd expect them. There was a type of malware that actually did this.... haven't seen it for quite awhile though. In the days that we used OTL, we used to add a custom scan to search for this: %USERPROFILE%\..|smtmp;true;true;true /FP Combofix also searched for this malware and is designed to remove it and move the folders/files back to the original location. The important thing was not to empty the temp files until this malware was removed. That was the reason we changed tactics and stopped emptying the temp files before starting the malware removal process. I'm not saying this is definitely the case here, just that it may be a possibility. 1 Quote
FPCH Staff Tony D Posted February 27, 2017 Author FPCH Staff Posted February 27, 2017 I'll have to get over there to run a scan. It has Emisosft's AntiMalware. Quote
starbuck Posted February 27, 2017 Posted February 27, 2017 Have a look for this folder....SMTMP If it exists, then the malware could be present. This very annoying Trojan virus creates the SMTMP folder in C:\Users\%User\AppData\Local\Temp\ folder and moves to it all files from Start and Desktop folders, basically screwing up users Start Menu and Desktop. It also modifies the moved files with hidden tag, so they are no longer visible to common users (with hidden files hidden in system). Quote
FPCH Staff Tony D Posted February 27, 2017 Author FPCH Staff Posted February 27, 2017 Thanks Starbuck. There was no SMTMP folder in that directory. I ran an Emsisoft AntiMalware scan this morning. Just some adware - Ask mostly. Quote
starbuck Posted February 27, 2017 Posted February 27, 2017 There was no SMTMP folder in that directory. Then I doubt that this malware is responsible then. It could be that something went wrong with the explorer.exe process. Quote
Recommended Posts