Solved

How can I find a specific file and delete some other files if found

Posted on 2014-11-01
3
291 Views
Last Modified: 2014-11-01
Hi,

We had a variant of CryptoLocker (CryptoWall) and I am trying to create a PowerShell script that will find the file "DECRYPT_INSTRUCTION.TXT" and if found somewhere, delete some other files (in that container or folder) like *.doc, *.pdf and *.xls.

I am pretty new to PowerShell and the client's latest backup is 2 weeks ago. So I want to only delete the encrypted files then replace them with the ones in the backup, without touching the rest of the files (we where been able to stop the virus progression quite early).

So far, I have been writing this test script but I have commented portions as I am not shure if the get-childitem is able to pipe a remove-item command and know that it's only in the directory it found the searched file:

get-childitem c:\PS\ -include DECRYPT_INSTRUCTION.TXT -recurse |`
foreach{
    $Item = $_
    $Type = $_.Extension
    $Path = $_.FullName
    $Folder = $_.PSIsContainer
    $Age = $_.CreationTime
   
    <#remove-item $_.fullname #>
    Write-Host $_.FullName " found in " $_.PSIsContainer

    <#get-childitem c:\PS\ -include *.doc, *.pdf, *.xls | `
    Foreach-Object{
        Write-Host $_.fullname
    }#>

}

Thank you for helping.
0
Comment
Question by:Emmanuel Nadeau
3 Comments
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 40417662
When you pipe an item, all the info about it is self-contained.
The following should work for you.  Remove the -whatif parameters to run for real.
Get-ChildItem C:\ps -include DECRYPT_INSTRUCTION.TXT -recurse | foreach `
{
    $_ | Remove-Item -WhatIf
    Get-ChildItem "$($_.Directory)\*" -include *.doc, *.pdf, *.xls | Remove-Item -WhatIf
}

Open in new window

0
 
LVL 68

Expert Comment

by:Qlemo
ID: 40417709
If possible, you should include the code to get the backup file after deleting the infected one. At least you need a full log of the infected files. This can be done e.g. by collecting the objects pre deletion:
Get-ChildItem C:\ps -include DECRYPT_INSTRUCTION.TXT -recurse | foreach `
{
    $_ | Remove-Item -WhatIf
    Get-ChildItem $_.Directory)\ -include *.doc, *.pdf, *.xls | tee -var delFiles | Remove-Item -WhatIf
    <# $delFiles contains the file objects, which can still be used though referring to deleted files #>
}

Open in new window

0
 

Author Comment

by:Emmanuel Nadeau
ID: 40417852
Thank you for your awnsers.

This solved my question.

By the way if anyone else reading this is wondering, the file types targeted by a CryptoLocker type virus are:

3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Create and license users in Office 365 in bulk based on a CSV file. A step-by-step guide with PowerShell script examples.
A procedure for exporting installed hotfix details of remote computers using powershell
This is Part 3 in a 3-part series on Experts Exchange to discuss error handling in VBA code written for Excel. Part 1 of this series discussed basic error handling code using VBA. http://www.experts-exchange.com/videos/1478/Excel-Error-Handlin…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now