?
Solved

Currpted Files Due to Virus

Posted on 2014-01-16
8
Medium Priority
?
503 Views
Last Modified: 2014-01-18
Corrupted Document Screenshot 1Corrupted Document Screenshot 2
I have an user whose PC was infected with "Crypto" virus on this computer last night and somehow so many WORD/EXECL files on the network drive (on Windows Server 2003/File Server) have been infected. When I try to open them, I see the screenshots.

Is there a simply program that will undo the damage?
0
Comment
Question by:sglee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 4

Accepted Solution

by:
Kent Fichtner earned 668 total points
ID: 39786183
I am sorry to say but as far as I am aware those files are encrypted, not corrupted.  I have looked and there are a lot of other people with the same issue.  The only solution that I know of is to restore a backup.
0
 
LVL 83

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 668 total points
ID: 39786287
Pay the ransom, restore from shadow copies, restore from backup are the only solutions. I am very sorry to say.
0
 
LVL 85

Assisted Solution

by:Scott McDaniel (Microsoft Access MVP - EE MVE )
Scott McDaniel (Microsoft Access MVP - EE MVE ) earned 664 total points
ID: 39786299
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:sglee
ID: 39786419
Excel ErrorUpon further investigation, I don't think it is an act of virus.
Reasons:
(1) I can open some WORD files.
(2) I can't open any of the EXCEL files so far. I tried to open 20 some excel files.
(3) All of those files that I can't open have older dates like 9/5/2011, 5/3/1009 ... etc. None of these have today's or yesterday's dates. If the virus opened/altered the contents of those files, they would have had recent dates, but that is not the case.

That leads me to think that maybe this problem is caused by something else. Maybe server hardware is failing? Windows updates (perhaps applied overnight) screwed things up? If the Windows update was the problem, that would have been on CNN by now.

I don't know what to make of it?

As to the backup, I found out they did not have good backup since 12/168/2013, so here is another problem.
0
 
LVL 85
ID: 39786462
Crypto may not have encrypted all of the documents, so it would be possible open some but not all. It's very obvious if Crypto was the culprit - the user should have seen the "ransom" screen on their machine at some point. It's an image that has "Your personal files are encrypted" at the top, a picture of a shield to the left, a countdown timer, etc etc.

If you know the machine was infected with Crypto. then AFAIK there's nothing you can do other than pay the ransom, restore from backup, or try to use the Shadow Copy workaround to get them back (as suggested earlier).
0
 

Author Comment

by:sglee
ID: 39786503
Viruses QuarantinedHere are the viruses in Quarantined.
0
 
LVL 4

Expert Comment

by:Kent Fichtner
ID: 39786598
I would say if it is that virus or not, if the files have been corrupted that means the data in the file has changed...then the only way to get it back is to restore it.  Either restore through system rollback or a restore though a backup.
0
 

Author Comment

by:sglee
ID: 39786617
I agree. Thanks for your help.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Access developers frequently have requirements to interact with Excel (import from or output to) in their applications.  You might be able to accomplish this with the TransferSpreadsheet and OutputTo methods, but in this series of articles I will di…
Instead of error trapping or hard-coding for non-updateable fields when using QODBC, let VBA automatically disable them when forms open. This way, users can view but not change the data. Part 1 explained how to use schema tables to do this. Part 2 h…
This Micro Tutorial demonstrates in Microsoft Excel how to consolidate your marketing data by creating an interactive charts using form controls. This creates cool drop-downs for viewers of your chart to choose from.
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question