I noticed about 3 weeks ago that a bunch (not all) of my picture and video files are gone!! The folders I had them arranged in are still there, but there is nothing in them. I have been loosing my mind trying to figure out the problem. I have requested the assistance of 3 of my good computer buddies and nothing. I recently purchased DiskInternals Uneraser and it seems it found my old pictures from one folder, but not from the new path I had been using for about 3 months. I am extremely upset. Can anyone please help me to recover my files???? I already ran the please read before posting section and followed all directions. PLEASE, PLEASE can anyone help me?????

Is it possible to extract the files from the file???


Here are my requested logs:


Malwarebytes' Anti-Malware 1.28
Database version: 1155
Windows 5.1.2600 Service Pack 3

9/15/2008 2:23:25 PM
mbam-log-2008-09-15 (14-23-25).txt

Scan type: Full Scan (C:\|)
Objects scanned: 195651
Time elapsed: 1 hour(s), 18 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 14
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{5269d0c0-572b-445a-88ac-8c8843b6d42b} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{69c1ef64-a396-4490-8849-52af7f7ec6e5} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{95e554e1-04f3-4d9b-a4e9-881dc420882b} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f5f40e25-cf4d-434e-a6ae-ed625ae87cab} (Trojan.Fakealert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88ebbe0b-5ff8-4b84-b043-71a216374a5b} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\mpfanvqg (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Janusware\ThumbsDb\ijl15.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F6751740-EB65-4F51-9F4B-AC268B6E20CE}\RP39\A0023575.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sherrie Metz\Favorites\Error Cleaner.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sherrie Metz\Favorites\Privacy Protector.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sherrie Metz\Favorites\Spyware&Malware Protection.url (Rogue.Link) -> Quarantined and deleted successfully.


ESET ONLINE SCANNER LOG:

# version=4
# OnlineScanner.ocx=
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3443 (20080915)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=5a27d035f3b9a94aa9f09cbe57e0d31f
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-09-15 08:12:51
# local_time=2008-09-15 04:12:51 (-0500, Eastern Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=352456
# found=0
# scan_time=5993

UNINSTALL LOG:

The only programs I did not recognize were the following:
Answer Works
Bonjour
Learn 2 Player

THANK YOU SO MUCH!!!

Dani AI

Generated

A few focused steps to take next (short, practical and safe).

As noted, thumbs.db only holds small Explorer thumbnails — not the original full‑resolution photos. That means thumbs.db can sometimes give tiny previews, but it will not restore your originals. Since already used a recovery tool and recovered some older files, the situation looks like partial metadata loss or overwritten NTFS entries rather than a simple rename.

Immediate do NOTs

  • Stop using the affected drive. Continued writes reduce recovery chances.
  • Do not run repair utilities (chkdsk, scandisk) on the live disk until you have an image.

Quick checks you can try (non-destructive)

  • Show hidden/system files in Explorer, or unhide with the command prompt:
    attrib -h -r -s /s /d "X:\path\to\folder\*.*"
  • Search the whole volume for image/video extensions (example):
    dir /s /b X:\*.jpg X:\*.jpeg X:\*.png X:\*.avi > C:\found_files.txt

    Perform these only to verify — avoid writing recovered files back to the same drive.

Safe recovery workflow (recommended)

  1. Make a full sector image of the disk to an external drive (use FTK Imager, dd/ddrescue from a Linux rescue USB, or a similar tool). Work from the image, never the original.
  2. Run file‑carving recovery tools on the image (PhotoRec, R‑Studio, Recuva, DiskInternals, etc.). Note: file carving recovers file content but usually loses original filenames and folder structure.
  3. If using Windows Vista/7/10, check Previous Versions / Shadow Copies (right‑click folder → Properties) or use a Shadow copy tool. This is less likely on XP but still worth checking if shadow copies exist.
  4. If recovery tools fail or files are critical, consider professional data recovery — they can handle MFT corruption and physical issues.

A final note on malware: some trojans hide files or create shortcuts. Make sure the system is clean (offline rescue scanner) before restoring recovered files. ’s program identification is helpful but not directly relevant to file recovery; focus on imaging and carving first.

Recommended Answers

All 2 Replies

Is it possible to extract the files from the file??? Thumbs.db contains only the low resolution thumbnails of your pictures that are displayed in explorer if you select that option in View.

The only programs I did not recognize were the following:
Answer Works=== has something to do corel or another program ,maybe
Bonjour===== is releated to I-Tunes
Learn 2 Player,= is a player installed with AOL or some other software maybe !

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.