Solved

How can I find a specific file and delete some other files if found

Posted on 2014-11-01
3
295 Views
Last Modified: 2014-11-01
Hi,

We had a variant of CryptoLocker (CryptoWall) and I am trying to create a PowerShell script that will find the file "DECRYPT_INSTRUCTION.TXT" and if found somewhere, delete some other files (in that container or folder) like *.doc, *.pdf and *.xls.

I am pretty new to PowerShell and the client's latest backup is 2 weeks ago. So I want to only delete the encrypted files then replace them with the ones in the backup, without touching the rest of the files (we where been able to stop the virus progression quite early).

So far, I have been writing this test script but I have commented portions as I am not shure if the get-childitem is able to pipe a remove-item command and know that it's only in the directory it found the searched file:

get-childitem c:\PS\ -include DECRYPT_INSTRUCTION.TXT -recurse |`
foreach{
    $Item = $_
    $Type = $_.Extension
    $Path = $_.FullName
    $Folder = $_.PSIsContainer
    $Age = $_.CreationTime
   
    <#remove-item $_.fullname #>
    Write-Host $_.FullName " found in " $_.PSIsContainer

    <#get-childitem c:\PS\ -include *.doc, *.pdf, *.xls | `
    Foreach-Object{
        Write-Host $_.fullname
    }#>

}

Thank you for helping.
0
Comment
Question by:Emmanuel Nadeau
3 Comments
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 40417662
When you pipe an item, all the info about it is self-contained.
The following should work for you.  Remove the -whatif parameters to run for real.
Get-ChildItem C:\ps -include DECRYPT_INSTRUCTION.TXT -recurse | foreach `
{
    $_ | Remove-Item -WhatIf
    Get-ChildItem "$($_.Directory)\*" -include *.doc, *.pdf, *.xls | Remove-Item -WhatIf
}

Open in new window

0
 
LVL 68

Expert Comment

by:Qlemo
ID: 40417709
If possible, you should include the code to get the backup file after deleting the infected one. At least you need a full log of the infected files. This can be done e.g. by collecting the objects pre deletion:
Get-ChildItem C:\ps -include DECRYPT_INSTRUCTION.TXT -recurse | foreach `
{
    $_ | Remove-Item -WhatIf
    Get-ChildItem $_.Directory)\ -include *.doc, *.pdf, *.xls | tee -var delFiles | Remove-Item -WhatIf
    <# $delFiles contains the file objects, which can still be used though referring to deleted files #>
}

Open in new window

0
 

Author Comment

by:Emmanuel Nadeau
ID: 40417852
Thank you for your awnsers.

This solved my question.

By the way if anyone else reading this is wondering, the file types targeted by a CryptoLocker type virus are:

3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Create and license users in Office 365 in bulk based on a CSV file. A step-by-step guide with PowerShell script examples.
A brief introduction to what I consider to be the best editor for PowerShell.
This is Part 3 in a 3-part series on Experts Exchange to discuss error handling in VBA code written for Excel. Part 1 of this series discussed basic error handling code using VBA. http://www.experts-exchange.com/videos/1478/Excel-Error-Handlin…
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now