New
#1
Disappearing Files & Programs
I'm posting this in hope those who experienced the same thing could share or those who had the slightest idea of what this may be to advise on this issue/threat.
Our configuration...
- All computers are running on Windows Home 10 2004 or later.
- All computers have secondary local user account Administrator activated using different password. Used for administration/troubleshooting purposes.
- All users are using only non-administrator user account to prevent installation or running of unknown software. They cant install software themselves or run critical programs that changes system settings.
Around mid February this year I've received a complaint from one of my users whose files just mysteriously disappeared. Upon checking I've found the following...
- Computer prompted various errors of missing links and programs upon logging into windows.
- Files (doc, xls & etc) had disappeared almost entirely from Documents, Desktops & Download folder.
- Files in Program Files, WindowsApps & Program Files (x86) had mostly disappeared. Folders for non-Microsoft programs had disappeared whilst Microsoft's programs had all disappeared.
- Shortcut links on desktop to programs had disappeared.
- Hard disk removed from computer and plugged into another.
- Used Recuva to check for deleted files but found nothing was deleted and nothing can be recovered.
- Used chkdsk and hard disk is reported healthy.
- Scanned for virus using Defender, Comodo Antivirus & Malwarebytes but found nothing.
At this point I'm guessing that it has to do with hard drive corruption and proceed to break the bad news to user.
Last week, another user reported of similar problem...
- User noticed a slight slowdown of computer.
- Windows prompted update and restart.
- Second day, user turned on computer and noticed and error prompted missing app from WindowsApp folder.
- Computer running slow with taskbar not responsive.
- Further checks shows that files (doc, xls & etc) from Documents, Desktop & Download are mostly missing.
- Shortcut links on desktop to programs had disappeared.
- Files in Program Files, WindowsApps & Program Files (x86) had mostly disappeared. Folders for non-Microsoft programs had disappeared whilst Microsoft's programs had all disappeared.
- Hard disk removed and checked with Recuva. More than 90% of files were found to be deleted and subsequently recovered.
- Run chkdsk and resulted in restoration of few cross linked files. Probably due to force shutdown by user due to windows not responding.
- Scanned for malware but found no traces.
- Plugged back in and looked through msconfig and each task in Task Scheduler but found nothing suspicious.
- No corrupted or temporary user profiles found.
From here, I'm trying hard not to relate both these existing users' experience but they look awfully similar.
This week, another user reported of similar condition. This time it happened in real-time in front of me...
- Computer running extremely slow. Checked Task Manager but found CPU idling at 1~5%, HDD idling at less than 25%, RAM was utilized at about 50%, Network isn't download anything heavy. Windows update not running.
- Any commands/click took approximately 2 minutes to happen.
- Taskbar not responsive.
- Able to finally use command prompt to run force shutdown command.
- Computer booted in safe mode. Computer appears to be slightly slow. Files are still intact. Nothing suspicious found.
- Computer rebooted into normal mode but stuck on boot-up. Forced power off.
- Computer booted again. Computer still slow.
- Shortcut links on desktop to programs had disappeared.
- Files in Program Files, WindowsApps & Program Files (x86) had mostly disappeared. Folders for non-Microsoft programs had disappeared whilst Microsoft's programs had all disappeared.
- Computer forced power off to prevent further files removal in case of virus.
- Hard drive removed and checked with Recuva. No user files (doc, xls & etc) deleted. Only files for programs.
- Apps & Features still shows all the list of software installed.
- Running programs (e.g. cmd, msconfig etc) as administrator failed prompting path not found. However, when running as normal user, programs like C:\Windows\system32\cmd.exe exists and runs normally.
- No error on chkdsk.
At this point, I can only related three of these computer to having their Program Files, WindowsApps & Program Files (x86) removed. By what? I'm unsure since no malware was detected. Backdoor trojan? Targeted hacking activity? Corrupted hard drive? Or simply Windows Update wiping off data for failed installation?