Solved

data recovery from possible virus

Posted on 2016-08-09
9
122 Views
Last Modified: 2016-08-11
Hello,

A friend of mine told me he has viruses on his USB drive, and it seems I’ve heard a virus of this type is going around; don’t know the exact name of the virus.

Apparently, what happens is the user of the flash drive is told all the documents on the flash drive are encrypted, and I was told something like calling giving your card #s or giving your #s through a web page.

I’ve scanned the flash drive w/ multiple antivirus software & no viruses have been found, but what has happened seems to be almost all documents on the drive or corrupt.

When you open a bmp file, you see the screen telling you your files are encrypted, yada, yada. I’ve attached a bmp file that shows the picture I’m talking about. There is no virus w/ this bmp file.

Microsoft Office 2010 files seem to be hit hard, and those are the files I need to recover if at all possible. I have Office 2010 too, and if there is a better repair function in later versions of Office…well they will not be available to me.
I’ve tried 2 evaluation versions of Office recovery software & nothing that looks anything good has been recovered; just a bunch of junk.

I’m attaching a word file that when you open it w/ Word says it corrupted do you want to repair the file. If you choose repair then you get the message “the file cannot be opened because there are problems w/ the contents.” Then you hit the details button you get “this file cannot be recovered because some parts are missing or invalid".

I’m not sure, but maybe this is what the virus was supposed to do and corrupt all the Office files, and apparently the picture type files too. There is a load of JPG file on the flash drive that get the corrupt message too. I’ve attached a JPG file, and hopefully there’s a way to open the file or a way to recover the file.

Does anyone know of a recovery software that may be able to get these documents back, may be another way to try to recover these documents, or just hopeless?

Garmin-heart-rate.docxThanks
README.bmp
s-l16001.jpg
0
Comment
Question by:kevluck373
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 94

Expert Comment

by:John Hurst
ID: 41749641
It sounds like you got the Cryptolock Ransomware virus. You cannot recover the documents and you must restore from a recent backup.
1
 
LVL 88

Expert Comment

by:rindi
ID: 41749659
It also won't just infect the USB disks, but also local and network locations. First install windows again from scratch on the infected PC, then as has been mentioned above, restore all your data from your backups.
1
 
LVL 32

Expert Comment

by:Paul Sauvé
ID: 41749664
just saying: from itworldcanada.com
Ransomware and rogue anti-spyware are the worst types of malware afflicting Canadian computers, EnigmaSoftware.com reports
http://www.itworldcanada.com/messagent.php?ID=u83u0UG_4Pz_TvzUrmuZqiCygfvEfaudGMnvj9zNtOxrALFKCJ84%2BhEFhufNRZ7pRgRS_fRmfAeyDLsvM2kXkcTlFbM09

I hope you have a recent backup
1
PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

 

Author Comment

by:kevluck373
ID: 41749725
I've been surfing the internet, and it seems there's a slim possibility you can download apps from places such as Kapersky to hopefully decrypt some of the file(s).

Most of the apps say you need a backup copy. The backup w/ office is known as the shadow copy, and I assume this is the file that's kept in the background to get a document back if say, the power goes out. There seems to be some apps that don't seem to mention shadow copies, but it seems you have to know the specific name of the virus to use one of these apps.

Since I've done many virus scans on the flash drive I'm not sure there is a way to find out which specific virus it could be.
0
 
LVL 94

Expert Comment

by:John Hurst
ID: 41749726
Decryption could take many years. You need to recover from backup. Kaspersky might be able to tell you what variant, but that does not change the outcome.
1
 
LVL 88

Accepted Solution

by:
rindi earned 500 total points
ID: 41749947
The ransomeware will have deleted any shadow copies, so you can forget those.
0
 

Author Comment

by:kevluck373
ID: 41752498
I did find out the infection on the drive is crypmic, and apparently has came up very recent.

There a few programs out there supposedly will decrypt files for other ransomware encryption but not this particular ransomware. Hopefully someday there will be some program that decrypt all the files.

I feel bad for him, but all I can do is urge to him to back frequent.

Thanks for your help
0
 

Author Closing Comment

by:kevluck373
ID: 41752508
I tried several ways to see if there were any shadow copies on the flash drive but didn't any.
0
 
LVL 94

Expert Comment

by:John Hurst
ID: 41752509
Why did you only select one answer here when several said similar things?
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will guide you to convert a grid from a picture into Excel format using Microsoft OneNote and no other 3rd party application.
Access developers frequently have requirements to interact with Excel (import from or output to) in their applications.  You might be able to accomplish this with the TransferSpreadsheet and OutputTo methods, but in this series of articles I will di…
This Micro Tutorial will demonstrate how to create pivot charts out of a data set. I also added a drop-down menu which allows to choose from different categories in the data set and the chart will automatically update.
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question