Recovering deleted files following pre-boot scan

My wife’s computer was recently infected with a Trojan Horse virus indicating an indexation problem. I downloaded and installed Avast free software and it immediately found the infection. I then chose to do a pre-boot scan. After a short time into the scan an infected file was found and this is where I think I made a mistake; I chose to delete the file. The scan then did that and continued to run, finding another infected file. I then chose to ‘delete all’ and away Avast went. This scan took over 5 hours to complete.

Now my wife has no pictures, documents, etc. The only thing I can think of is that I should have selected some action other than ‘delete all’; repair maybe.

Is there a way to recover all the lost data files? I’m in real trouble.

Thanks

sorry…you went for the option…that have no more options

Clean, Quarantine, or Delete?
http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm

Deletion is never a good first option, you have none left.

The only way to recover deleted files is through an application to recover deleted files (google that, there should be plenty of options, many free). The longer between deletion and any recovery attempt, the less likely the success rate.

You would also have to know what it is that you seek to recover (date, time of deletion roughly) as there could be hundreds of hits in its search for deleted files. Avast may well alert when trying to recover these files, if so sending to the chest is the best/safest option.

Look in the C:\Documents and Settings\All Users\Application Data\Avast Software\Avast\report\aswBoot.txt file (XP location) C:\ProgramData\Avast Software\Avast\report\aswBoot.txt (Vista, Win7 location), check this file using notepad for info on the scan/detections, etc.

Copy and paste that information, file name, location and malware name of the detections. That gives us something to work with (and also when you attempt to undelete these files), to say what the likelihood of the detection being good.

I find it rather unlikely that the images and documents were infected (and removed)…

maybe something for Essexboy and his Harry potter tools then ?

Wouldn’t restoring bring back the lost files ??? otherwise there is this nice little recovery tool by Piriform http://www.piriform.com/recuva

They are not lost - just hidden

Lets get them back for you

[*] Download RogueKiller and save it on your desktop.
[*]Quit all programs
[*] Start RogueKiller.exe.
[*] Wait until Prescan has finished …
[*] Click on Scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRScan.png

[*]Wait for the end of the scan.
[*] The report has been created on the desktop.
[*] Click on the Delete button.

http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRDelete.png

[*]The report has been created on the desktop.

[*]Next click on the ShortcutsFix

http://i1224.photobucket.com/albums/ee362/Essexboy3/RogueKiller/RGKRShortcutsFix.png

[*]The report has been created on the desktop.

Please post: All RKreport.txt text files located on your desktop.

THEN

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%*.exe
/md5start
consrv.dll
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
C:\Windows\assembly\tmp\U*.* /s
%Temp%\smtmp\1*.*
%Temp%\smtmp\2*.*
%Temp%\smtmp\3*.*
%Temp%\smtmp\4*.*
Drives
CREATERESTOREPOINT

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Post both logs

AND FINALLY

Download aswMBR.exe ( 4.1mb ) to your desktop.
Double click the aswMBR.exe to run it Click the “Scan” button to start scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRScan.gif

On completion of the scan click save log, save it to your desktop and post in your next reply

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRsavelog.gif

I’m overwhelmed by the response from all of you–thanks. I’ve begun to download programs and compile the information requested and will post soon.

I believe the Trojan that started all this was Win32:FakeSysdefs-A as indicated in the Avast pre-boot scan log I have saved and will include in a future post.

Thank you again!

please help me to recover my pictures which are very important to me…i have attached the reports of roguekiler…please help me…

Helping multiple users in the same topic will be chaos

Start your own topic where you explain the problem