Solved

Doc, Xls, and Pdfs act like they are corrupt on desktop

Posted on 2014-01-09
7
519 Views
Last Modified: 2014-01-15
A user has several folders on their win 7 desktop that contain pdfs, doc, docx, and xls files. When we try to open them it says they are corrupt. Any files of the same extention that are saved in other locations on the HD do not say this. Can you help?
0
Comment
Question by:portillosjohn
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 

Author Comment

by:portillosjohn
ID: 39768239
On closer inspection it is all docs and docs on the computer. I have already scanned with malware bytes and eset and it finds nothing.
0
 
LVL 62

Expert Comment

by:☠ MASQ ☠
ID: 39770254
Check JPEGs as well.  If it's all Office files and common image formats this is Cryptolocker.

An Offline scan should find the infective component which is hidden while active on the machine.  If the infection was Cryptolocker then you've almost certainly lost the data :(

See: http://www.experts-exchange.com/Security/Encryption/Q_28295419.html
0
 

Author Comment

by:portillosjohn
ID: 39771371
Its not all the jpegs. Just one folder on the destkop. I can't find any evidence that it is cryptolocker. Plus no ransom message.
0
Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

 
LVL 62

Expert Comment

by:☠ MASQ ☠
ID: 39771837
Are the only files affected in the one folder or is it just JPEGs in one folder that are affected?

Check your eset logs to see if anything has been removed or quarantined recently
0
 

Author Comment

by:portillosjohn
ID: 39771919
It seems to be only JPEGs in one folder that are affected. The logs came up blank as well...Really wierd.
0
 
LVL 62

Accepted Solution

by:
☠ MASQ ☠ earned 500 total points
ID: 39771967
If you're certain the system is clean I'd still suspect you're looking at ransomware damage - you won't get a message on the screen until all the indexed files are encrypted so if the payload was removed by AV or anti-malware tools only some files will be affected and the damage becomes apparent.  These nasties tend to index the HDD and then work their way sequentially through the file structure so look to see if the locations could be indexed in order. you may find a folder that's only part encrypted which is the point at which the damage was stopped.  

The lack of a cleanup log indexing a ransomware signature undermines this but the pattern of Office files and JPEGs is consistent with that kind of infection.
0
 

Author Closing Comment

by:portillosjohn
ID: 39782587
Looks like it was the cryptolock. The user had backups which he did not tell me at the start......
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently Microsoft released a brand new function called CONCAT. It's supposed to replace its predecessor CONCATENATE. But how does it work? And what's new? In this article, we take a closer look at all of this - we even included an exercise file for…
Outlook Free & Paid Tools
This video shows the viewer how to set up and create Footnotes in their document. Click on the References tab: Select "Insert Footnote": Type in desired text:
This video shows where to find templates, what they are used for, and how to create and save a custom template using Microsoft Word.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question