Solved

Network share

Posted on 2014-04-05
11
315 Views
Last Modified: 2014-04-08
Hi

Since today morning I have a weird problem. On one of my network share when I try to open a .DOC .XLS or a .PDF I receive a message that says

The file format differs from the format that the file name extension specifies.

If I clic on OK the file is opening and all the text Inside is ASCII.

It is happening on the entire share. But only this share. The others share are OK.
0
Comment
Question by:jpmoreau
11 Comments
 
LVL 34

Expert Comment

by:Dan Craciun
Comment Utility
Check if the files are not encrypted. You could of been hit by CryptoLocker or similar.

I mean another computer with access to that share is infected.
If that's the case, remove it from the network, clean it, restore files from backup.

HTH,
Dan
0
 
LVL 25

Expert Comment

by:Tony Giangreco
Comment Utility
Are you sure there isn't spyware on the Pc your accessing it from?

Here are some apps to check it with
AdwCleaner
http://www.bleepingcomputer.com/download/adwcleaner/

Kaspersky TDSSKiller
http://www.bleepingcomputer.com/download/tdsskiller/

ESET online scanner
http://www.eset.com/us/online-scanner/

Malwarebytes Anti-Rootkit
http://www.bleepingcomputer.com/download/malwarebytes-anti-rootkit/

www.malwarebytes.org
www.superantispyware.com
www.hitmanpro.com
0
 

Author Comment

by:jpmoreau
Comment Utility
It is happening from any of the pc's
0
 
LVL 34

Expert Comment

by:Dan Craciun
Comment Utility
You can post here a document that you know does not contain sensitive data so we can confirm it's encrypted.

In the mean time, check the local documents of the other computers. I bet at least one has all documents encrypted. That's the infected one...
0
 

Author Comment

by:jpmoreau
Comment Utility
The documents that are in problem are on a server share. Here is one example

Thanks
Besoins-des-clients-2012.xls
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 34

Expert Comment

by:Dan Craciun
Comment Utility
Looks encrypted. No header, no identifiable content inside.

The way Cryptolocker works, it encrypts all documents on local folders and on accessible network shares.
0
 

Author Comment

by:jpmoreau
Comment Utility
Ok

What is the best way to correct?

Is there an easy way?
0
 
LVL 34

Expert Comment

by:Dan Craciun
Comment Utility
Yup. Find the infected machine(s), remove it/them from the network, clean them, then restore all files from backups.

Read this if you're infected with CryptoLocker (you might have a different virus, as variants appeared): http://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information
0
 

Author Comment

by:jpmoreau
Comment Utility
I cannot not determine if I'm infected or not. Ihave try the tools but nothings show me taht I'm infected
0
 
LVL 34

Expert Comment

by:Dan Craciun
Comment Utility
If your files are encrypted, it means some software encrypted it. You just need to find it.
0
 
LVL 10

Accepted Solution

by:
cpmcomputers earned 500 total points
Comment Utility
In most cases the cryptolocker (and similar)
Infect from a client pc on the network not usually the server itself not the one necessarily you are logging in from
You need to check all the pc's on the network

Please also check this article

http://www.theregister.co.uk/2014/04/03/cryptodefense_rsa_private_key_on_disk/

A new variant is out
0

Featured Post

How to Backup Ubuntu to Amazon S3

CloudBerry Backup offers automatic cloud backup and restoration for Linux. It has both GUI and command line interface (CLI) ensuring its flexibility in use. Find out more

Join & Write a Comment

Suggested Solutions

Preface There are many applications where some computing systems need have their system clocks running synchronized within a small margin and eventually need to be in sync with the global time. There are different solutions for this, i.e. the W3…
If, like me, you have a lot of Dell servers in the estate you manage this article should save you a little time. When attempting to login to iDrac on any server I would be presented with two errors. The first reads "Do you want to run this applicati…
The view will learn how to download and install SIMTOOLS and FORMLIST into Excel, how to use SIMTOOLS to generate a Monte Carlo simulation of 30 sales calls, and how to calculate the conditional probability based on the results of the Monte Carlo …
The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now