Folders empty after virus attack!!

Savagebme

Member
I experienced a "Fake-alert" Trojan attack... MalwareBytes was able to eliminate it, But all the contents of my folders show "empty"..My hard drive data shows the same content, So it is as if the files are there, But invisible...I have tried system recovery, But it error messages me back that it has failed... VERY confused...Help!!
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Hello and welcome I wish you would have contacted the forum first because doing a system restore you have probable infected your computer again.

You should always delete the restore points in you computer after an attact and start new ones. Now I will research your problem and get back to you shortly.
 

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
Thank You, The restore failed, But since then I have scanned with Microsoft Essentials.MalwareBytes And Spybot..Other than some cookies, Nothing there...
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Hello the best way to do this is to do a system restore by going back to where there would be no possibilty of the malware beyond that restore... Here are your choices on a system restore.

http://www.vistax64.com/tutorials/66971-system-restore.html

http://www.vistax64.com/tutorials/194765-system-recovery-options.html

http://www.vistax64.com/tutorials/76905-system-restore-how.html


You also might want to read number 3 of this tutorial...

http://www.vistax64.com/tutorials/116415-regedit-enable-disable.html
 

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
I did try a earlier than the attack restore point...But same thing, went through all of the motions, but at the end errored back that it as unable to complete...
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Hello look in the Event Viewer and see what errors there are when this happens and then upload them to us so we can see what's going on.
 

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
Antimalware event began on 04/01/2011 at 11:49:59...I did not find error codes, But I did find this in the event log within the system logs....

+System
-Provider[ Name] Microsoft Antimalware
-EventID1116[ Qualifiers] 0
Level3Task0Keywords0x80000000000000-TimeCreated[ SystemTime] 2011-04-02T06:49:59.000Z
EventRecordID267748ChannelSystemComputerwyatt-PCSecurity

-EventData
%%8603.0.8107.0{4A6A00AF-B08B-4D32-9875-5BB833DE2CDF}2011-04-02T06:49:29.307Z2147644377Exploit:Java/Midseq.A5Severe30Exploithttp://go.microsoft.com/fwlink/?linkid=37020&name=Exploit:Java/Midseq.A&threatid=2147644377113%%818C:\Program Files\Internet Explorer\iexplore.exewyatt-PC\wyattcontainerfile:_C:\Users\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\\AppData\Roaming\Sun\Java\Deployment\cache\javapi\v1.0\jar\javajsm.jar-12dbdc42-50126687.zip;file:_C:\Users\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\AppData\Roaming\Sun\Java\Deployment\cache\javapi\v1.0\jar\javajsm.jar-12dbdc42-50126687.zip->pap.class4%%8471%%8130%%82209%%8870x00000000The operation completed successfully. 00No additional actions requiredAV: 1.101.691.0, AS: 1.101.691.0, NIS: 9.134.0.0AM: 1.1.6702.0, NIS: 2.0.5854.0

%%860
3.0.8107.0
{4A6A00AF-B08B-4D32-9875-5BB833DE2CDF}
2011-04-02T06:49:29.307Z


2147644377
Exploit:Java/Midseq.A
5
Severe
30
Exploit
Encyclopedia entry: Exploit:Java/Midseq.A - Learn more about malware - Microsoft Malware Protection Center
4

2
3
%%818
C:\Program Files\Internet Explorer\iexplore.exe
wyatt-PC\

containerfile:_C:\Users\\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\\AppData\Roaming\Sun\Java\Deployment\cache\javapi\v1.0\jar\javajsm.jar-12dbdc42-50126687.zip;file:_C:\Users\\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\\AppData\Roaming\Sun\Java\Deployment\cache\javapi\v1.0\jar\javajsm.jar-12dbdc42-50126687.zip->pap.class
4
%%847
1
%%813
0
%%822
0
3
%%808

0x00000000
The operation completed successfully.

0
0
No additional actions required
-PC\

AV: 1.101.691.0, AS: 1.101.691.0, NIS: 9.134.0.0
AM: 1.1.6702.0, NIS: 2.0.5854.0
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Hello

I want you to download malwarebytes. After you download it then run the update to make sure it is current. Then run a full scan using malwarebytes. I will give the link at the bottom of the page. After the scan malwarebytes will save a copy of the whole scan, when it is done with it's scan you will be able to see in red if there are any malware, trojans left on your computer and then it will need your permission to get rid of it and of course the answer to that will be yes...

First things first as they say but please do this one right away here is the link, download the free version...

Malwarebytes

After this is finished post back with the results. Do NOT!!! use any restore points for doing a system restore because it can reinfect your system, we will talk about that later...
 

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
Ok....Will do...!!
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Ok, MalWarebytes found a couple of critters...Malwarepack, And buried them... But,..... Still no files... I have to quit for the day, Been On this for HOURS, Maybe something else will come up??? Thank You for all of your Help/Advice...Will check back Later...
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
We will continue to look for answers for you, thank you for letting me know about the malware and please do not use any of your restore points at all as you may reinfect your system again you will need to delete the restore points and make new ones...
 

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
Im updating here...same issue, I was wondering, What if I tried a alternate program to open these files? mostly i am wanting to recover my photos and music files...Any free software?
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
thanks again!! Picasa does not see the missing files..However MS Essentials detects them when I scan the folders....They are still there, Just invisible...
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Update...Copied folder to an SD card, Plugged in to Laptop, Files appear and open on Laptop...They have a kinda ghost image, But seem to be perfectly intact....Plug back in to my PC, Same thing "Folder Empty"....

Any ideas??
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
Hi,
After you have copied files to SD card, & although ghostly they are intact.
Have you tried copying those images,in other words copying the copy, place in a new file & see what is visible on the PC?
Worth a try, you still have a copy on the SD card so you don't loose them.
Thank you.
 

My Computer

System One

  • Manufacturer/Model
    Hewlett-Packard SR5019UK
    CPU
    AMD Athlon 64 processor 3800 + 2.40GHz
    Motherboard
    M2N68-LA (Narra)
    Memory
    2.50GB
    Graphics Card(s)
    nVidia GeForce
    Sound Card
    Realtec ALC888 Audio
    Monitor(s) Displays
    17" LCD Monitor
    Hard Drives
    160 Gb Usable Hard Drive
    Other Info
    HP G56 Laptop Win 7 64bit. 4Gb Ram DDR2's. Hitachi 450Gb Hard Drive. Pentium(R) Duel-Core CPU.
I tried that, Even gave the folder a new name...Still will not show files...SOOO, I have an external drive that I will copy the folders to, Possibly move them to another computer, ( After i Virus scan the HELL out of it....!!) Then, Who Knows, Maybe burn it to a CD?? Seems all files have had their Properties changed?? Havent checked that out yet...But it does seem like were getting closer....
 

My Computer

System One

  • CPU
    intel core duo cpu e8500 3.16 ghz 3.17 ghz
    Motherboard
    acpi x 86
    Graphics Card(s)
    nvidia geforce 9800 gt
    Sound Card
    realtek
    Monitor(s) Displays
    acer e151h
    Hard Drives
    wdc wd50
I think your right, obviously amaricancritic has been dealing with this mainly, so his thoughts are important I think.
But I think he will agree that you are in a position to save the files you want to an external point.
Then your going to have to do a complete clean, I would think.
What are your thoughts?
 

My Computer

System One

  • Manufacturer/Model
    Hewlett-Packard SR5019UK
    CPU
    AMD Athlon 64 processor 3800 + 2.40GHz
    Motherboard
    M2N68-LA (Narra)
    Memory
    2.50GB
    Graphics Card(s)
    nVidia GeForce
    Sound Card
    Realtec ALC888 Audio
    Monitor(s) Displays
    17" LCD Monitor
    Hard Drives
    160 Gb Usable Hard Drive
    Other Info
    HP G56 Laptop Win 7 64bit. 4Gb Ram DDR2's. Hitachi 450Gb Hard Drive. Pentium(R) Duel-Core CPU.
Hello Savagebme

I am going to ask someone in the forum if they would take a look at your post and see if we can come up with some good answer's for you, I hope you don't mind.


americancritic
 

My Computer

System One

  • Manufacturer/Model
    a6530f Desktop
    CPU
    HP-PAVILION
    Motherboard
    M2N68-LA (Narra3)
    Memory
    8 Gigs of Ram/DDR2 PC2-6400 MB/sec
    Graphics Card(s)
    NVIDIA GeForce 6150SE nForce 430
    Sound Card
    Intergrated Realtex ALC888S Audio
    Monitor(s) Displays
    LG W40 series widescreen
    Screen Resolution
    1600 X 900
    Hard Drives
    1 640 GB Sata transfer rating: 3.0 Gb/sec speed: 7200 RPM
    PSU
    300W
    Case
    Mid-Size ATX
    Keyboard
    HP Multimedia Keyboard
    Mouse
    Microsoft Wireless Mouse 5000
    Other Info
    Processor: AMD Phenom X3 8450 Operating speed: Up to 2.1 GHz, Number of cores: 3, Socket: AM2+, Bus speed: 3600 MHz HT3 (clocked down to 2000 MHz)

    Modem: 56K WinModem/

    Supermulti: 16X DVD(+/-)R/RW 12X Ram (+/-)R DL Lightscribe SATA Drive

    Menory Card Reader: 15-in-1 Multimedia Card Reader

    Media Drive
Back
Top