Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Doc, Xls, and Pdfs act like they are corrupt on desktop

Posted on 2014-01-09
Medium Priority
Last Modified: 2014-01-15
A user has several folders on their win 7 desktop that contain pdfs, doc, docx, and xls files. When we try to open them it says they are corrupt. Any files of the same extention that are saved in other locations on the HD do not say this. Can you help?
Question by:portillosjohn
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3

Author Comment

ID: 39768239
On closer inspection it is all docs and docs on the computer. I have already scanned with malware bytes and eset and it finds nothing.
LVL 63

Expert Comment

by:☠ MASQ ☠
ID: 39770254
Check JPEGs as well.  If it's all Office files and common image formats this is Cryptolocker.

An Offline scan should find the infective component which is hidden while active on the machine.  If the infection was Cryptolocker then you've almost certainly lost the data :(


Author Comment

ID: 39771371
Its not all the jpegs. Just one folder on the destkop. I can't find any evidence that it is cryptolocker. Plus no ransom message.
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 63

Expert Comment

by:☠ MASQ ☠
ID: 39771837
Are the only files affected in the one folder or is it just JPEGs in one folder that are affected?

Check your eset logs to see if anything has been removed or quarantined recently

Author Comment

ID: 39771919
It seems to be only JPEGs in one folder that are affected. The logs came up blank as well...Really wierd.
LVL 63

Accepted Solution

☠ MASQ ☠ earned 2000 total points
ID: 39771967
If you're certain the system is clean I'd still suspect you're looking at ransomware damage - you won't get a message on the screen until all the indexed files are encrypted so if the payload was removed by AV or anti-malware tools only some files will be affected and the damage becomes apparent.  These nasties tend to index the HDD and then work their way sequentially through the file structure so look to see if the locations could be indexed in order. you may find a folder that's only part encrypted which is the point at which the damage was stopped.  

The lack of a cleanup log indexing a ransomware signature undermines this but the pattern of Office files and JPEGs is consistent with that kind of infection.

Author Closing Comment

ID: 39782587
Looks like it was the cryptolock. The user had backups which he did not tell me at the start......

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article helps those who get the 0xc004d307 error when trying to rearm (reset the license) Office 2013 in a Virtual Desktop Infrastructure (VDI) and/or those trying to prep the master image for Microsoft Key Management (KMS) activation. (i.e.- C…
Cancel future meetings from user mailboxes in Office 365 using Remove-CalendarEvents
The viewer will learn how to use the =DISCRINV command to create a discrete random variable, use this command to model a set of probabilities and outcomes in a Monte Carlo simulation, and learn how to find the standard deviation of a set of probabil…
The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question