Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How can I find a specific file and delete some other files if found

Posted on 2014-11-01
3
Medium Priority
?
313 Views
Last Modified: 2014-11-01
Hi,

We had a variant of CryptoLocker (CryptoWall) and I am trying to create a PowerShell script that will find the file "DECRYPT_INSTRUCTION.TXT" and if found somewhere, delete some other files (in that container or folder) like *.doc, *.pdf and *.xls.

I am pretty new to PowerShell and the client's latest backup is 2 weeks ago. So I want to only delete the encrypted files then replace them with the ones in the backup, without touching the rest of the files (we where been able to stop the virus progression quite early).

So far, I have been writing this test script but I have commented portions as I am not shure if the get-childitem is able to pipe a remove-item command and know that it's only in the directory it found the searched file:

get-childitem c:\PS\ -include DECRYPT_INSTRUCTION.TXT -recurse |`
foreach{
    $Item = $_
    $Type = $_.Extension
    $Path = $_.FullName
    $Folder = $_.PSIsContainer
    $Age = $_.CreationTime
   
    <#remove-item $_.fullname #>
    Write-Host $_.FullName " found in " $_.PSIsContainer

    <#get-childitem c:\PS\ -include *.doc, *.pdf, *.xls | `
    Foreach-Object{
        Write-Host $_.fullname
    }#>

}

Thank you for helping.
0
Comment
Question by:Emmanuel Nadeau
3 Comments
 
LVL 41

Accepted Solution

by:
footech earned 2000 total points
ID: 40417662
When you pipe an item, all the info about it is self-contained.
The following should work for you.  Remove the -whatif parameters to run for real.
Get-ChildItem C:\ps -include DECRYPT_INSTRUCTION.TXT -recurse | foreach `
{
    $_ | Remove-Item -WhatIf
    Get-ChildItem "$($_.Directory)\*" -include *.doc, *.pdf, *.xls | Remove-Item -WhatIf
}

Open in new window

0
 
LVL 72

Expert Comment

by:Qlemo
ID: 40417709
If possible, you should include the code to get the backup file after deleting the infected one. At least you need a full log of the infected files. This can be done e.g. by collecting the objects pre deletion:
Get-ChildItem C:\ps -include DECRYPT_INSTRUCTION.TXT -recurse | foreach `
{
    $_ | Remove-Item -WhatIf
    Get-ChildItem $_.Directory)\ -include *.doc, *.pdf, *.xls | tee -var delFiles | Remove-Item -WhatIf
    <# $delFiles contains the file objects, which can still be used though referring to deleted files #>
}

Open in new window

0
 

Author Comment

by:Emmanuel Nadeau
ID: 40417852
Thank you for your awnsers.

This solved my question.

By the way if anyone else reading this is wondering, the file types targeted by a CryptoLocker type virus are:

3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Previously, on our Nano Server Deployment series, we've created a new nano server image and deployed it on a physical server in part 2. Now we will go through configuration.
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This is Part 3 in a 3-part series on Experts Exchange to discuss error handling in VBA code written for Excel. Part 1 of this series discussed basic error handling code using VBA. http://www.experts-exchange.com/videos/1478/Excel-Error-Handlin…
Loops Section Overview

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question