PDA

View Full Version : All Outlook mail, contacts etc. deleted by Spybot2.2



Stevinoz
2014-01-19, 02:46
Spybot found some trojans in my outlook data files and deleted them on the last scan, I didn't think it would delete the whole file but on my next reboot Outlook.pst and 2 saved pst archives were gone.

Spybot - Search & Destroy version: 2.1.18.131 DLL (build: 20130516)

What a nightmare to then join this forum, having to recover a backup of pst files 2 days old then wade through all the email (lucky I keep it on the server for a few days), then check my sync where I noticed that after the scan it had sync'd with my phone deleting all my future appointments, then get the confirmation email from this forum.

Found under Systen Scan menu/show previous logs:
Trojan.Agent.BACN;Trojan.GenericKD.1187337;Trojan.VIZ.Gen.1;Trojan.VIZ.Gen.1;Trojan.VIZ.Gen.1;Trojan.VIZ.Gen.1;Trojan.VIZ.Gen.1;Trojan.Downloader.JQAT;Trojan.Downloader.JQAT;Trojan.Downloader.JQAT;Trojan.Downloader.JQAT;Trojan.Downloader.JQAT;Trojan.Downloader.JQAT: [SBI $SpybotAV] Executable (File, nothing done)
C:\Users\Steve\Documents\outlook\Outlook.pst
Properties.size=1253270528
Properties.md5=D41D8CD98F00B204E9800998ECF8427E
Properties.filedate=1389734780
Properties.filedatetext=2014-01-15 07:56:19

Trojan.Generic.KDV.621787;Trojan.Generic.KDV.659200;Gen:Variant.Kazy.80952;Trojan.Script.477225;Trojan.Script.477225;Trojan.Script.477342;Trojan.Script.477342;Trojan.Generic.KDV.712678;Trojan.Generic.KDV.745745;Trojan.Generic.8438384;Trojan.Generic.KDV.769911: [SBI $SpybotAV] Executable (File, nothing done)
C:\Users\Steve\Documents\Outlook Files\archive2012.pst
Properties.size=2555028480
Properties.md5=46DBECDD9ED6BFBE53A4699366FBC1D8
Properties.filedate=1384954466
Properties.filedatetext=2013-11-21 00:04:25

Exploit.CVE-2012-0158.Gen;Exploit.CVE-2012-0158.Gen;Exploit.CVE-2012-0158.Gen;Exploit.CVE-2012-0158.Gen;Trojan.GenericKD.1030257;Trojan.GenericKD.1030257;Trojan.GenericKD.1035641;Trojan.VIZ.Gen.1;Trojan.VIZ.Gen.1;Trojan.VIZ.Gen.1;Trojan.GenericKD.1105798;Trojan.GenericKD.1105798: [SBI $SpybotAV] Executable (File, nothing done)
C:\Users\Steve\Documents\Outlook Files\archive2013.pst
Properties.size=806568960
Properties.md5=D41D8CD98F00B204E9800998ECF8427E
Properties.filedate=1389734325
Properties.filedatetext=2014-01-15 07:48:44

Even though it shows "(File, nothing done)" I did process all entries, admittedly there was a few emails with attached Trojans that I had not opened and did not delete, but to lose the whole file on reboot?

Cheers, Steve

tashi
2014-01-19, 05:05
Hello Stevinoz,

I left a link directing detectives to this topic and the older thread (http://forums.spybot.info/showthread.php?60505-All-mail-contacts-etc-deleted-from-Microsoft-Outlook) too as new posts have been added.

Thank you. :)

(m/f)
2014-01-20, 10:58
Hi Stevinoz,

I read your post here and I was looking for clues what might have caused the trouble. Then I saw this: "[SBI $SpybotAV]". It seems that our AV engine which we get from a partner caused this. We will report this FP to them. The good thing is: The Free Edition is not affected by that.

(m/f)
2014-02-07, 14:05
Hi again. This is a bit weird and we cannot simply create a similar situation here. We are still investigating how this has happened. If you have any more details for us this could help a lot. Another strange thing is that the md5 hash of 2 of the files is the one for an empty file: md5=D41D8CD98F00B204E9800998ECF8427E. Thank you for your patience.

(m/f)
2014-02-13, 14:26
We were finally able to reconstruct what happened. This issue will probably be already fixed in the next version. Thank you for reporting this.