Endpoint Protection

Expand all | Collapse all

Some Virus has corrupted many of our Microsoft Office files and PDF files.

ℬrίαη10-04-2013 08:28 PM

  • 1.  Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 02:31 PM

    We have an issue where many of our Microsoft Office files (excel, word) and pdf files have been corrupted.  I get errors saying that the 'File is not in a recognizable format' for excel.  The PDF files says that it's not a supported file. 

    Even pictures files are corrupt.  Excel and Work will open the file but it is all garbage characters everywhere.

    We are on an older version of SEP (11.0.6300.803) and I'm working on getting the update.  Is this a known virus?  Can we recover these corrupted files?

    Our backup retention period pass so I could not recover from backup.

    Please help!!!

    Thanks,

    Jasper



  • 2.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 02:34 PM

    Is anything showing in the SEP clients risk log?



  • 3.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 03:05 PM

    There are a few items that showed up on the risk log.

    Trojan.Gpcoder.E

    Downloader

    Trojan.Maljava!gen17

    Infostealer.Bancos

    Trojan.Dropper

     

    I looked these up and none of them seem to cause the issue we are having.  Either way, I have been taking each one of these machines and wiping them clean just to be on the safe side.

    Thanks!

    Jasper



  • 4.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 05:58 PM

    We too were just hit this afternoon.  All WORD, EXCEL, and now we see PDF's are all corrupted.  I noticed one user on are terminal server accessing 800-900 files at a time.  I suspect that his session is the soruce of the attack. 

    I have run a FULL scan using 12.1.3001.165 and it found NOTHING ! ! !

    Nothing in any logs.

    Do not want to restore from backup, if I can't detect where the problem is.

     

    HELP Symantec?



     



  • 5.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 06:08 PM

    I would open a case immediately and get a sample submitted

    http://www.symantec.com/security_response/submitsamples.jsp

    Also, try running the symhelp tool

    How to collect and submit to Symantec Security Response suspicious files found by the SymHelp utility

    Article:TECH203027  |  Created: 2013-02-21  |  Updated: 2013-05-23  |  Article URL http://www.symantec.com/docs/TECH203027

     

     



  • 6.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 08:19 PM
      |   view attached

    So I click on yhe link, and I get A symanctec page saying UNIVAILABLE.  Great!



  • 7.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-04-2013 08:28 PM

    Which one?

    Both are working for me.



  • 8.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-06-2013 07:34 AM

    Hi Jasper and Support-mcc,

    Ther are a lot of threats in circulation that will encrypt documents on a victim's computer and then prompt for a ransom to be paid to unlock them.  In many cases the file extension of Offic documents is changes to .crypt or similar, and the author has made it clear how to make contact and pay them.  (There is no guarantee that that an unlocking method even exists.  Often times they will just keep demanding more and more money from anyone who they have caught.)

    Unless you are seeing such a note from the malware author, there's no guarantee that what you are seeing is in fact ransomlock.  Perform a Load Point Analysis check on affected computers using the Symhelp tool, but also make sure that your Adobe or MS product is working correctly.    

    Do isolate any affected computers, submit any suspicious files that you find, and (above all) make sure that all of your important materials are backed up.  The defnese against these ransomlockers is to block the malicious process.  Any files already encrypted will not be recovered by SEP.

     



  • 9.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-06-2013 08:24 AM

    Hello,

    This virus does not ransom our files.  There is no prompt beside the one that says the file format is not recognized.

    This virus just corrupts the files.  Virus scans show NO infected computers at this point.  I will try to perform a load point analysis and post the results as soon as I can.  As for the backup, our backup retention period has passed and we no longer have a clean backup.  The symtoms were identified too late.

    Any help would be greatly appreciated!!!

    Thanks!

    Jasper



  • 10.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-08-2013 07:09 AM

    I am also having the same issue.  Had a user report this issue with file on his C: drive last week.  Then it was reported with files on the server yesterday and I was told the problem has been there for 2 weeks!  Office files, PDFs and now their quickbooks files are corrupt.  Not sure what else.  Haven't found any virus yet and no messages wanting money.



  • 11.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-08-2013 09:30 AM

    Had this issue as well this Sunday.  Shared drive on server and local workstation had all DOC, XLS and PDF files corrupted as described by OP.  However, all JPEG files remained unaffected.  Had to restore drives with recent backup.   Got past Symantec Endpoint Protection with all current update but Trojans were detected and cleaned during full scan on Sunday-  Trojan.Ransomcrypt.F, Trojan Gen.2 and Trojan.Zeroaccess.C  However the scan found too late,  after the  files were corrupted.



  • 12.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-08-2013 10:22 AM

    I have submitted the issue to Symantec.  Hopefully I can shed some light on this soon.

    I'll keep everyone posted. 

     

    Jasper



  • 13.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-08-2013 02:49 PM

    Symantec thinks it is a cryto logger virus.  Although there is no indication of this on our network. 

    However, they said there is no way to recover the lost data.

    Does anybody know of any software that can recover corrupt excel, word and pdf files?

    Thanks,

    Jasper



  • 14.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-08-2013 05:28 PM

    Also got several users with the same problem running Windows 7 pro SPK1 with MS Office 2007 and 2010. Updated Engine to 12.8.6.37. Fun thing is that when you open new Office or Acrobat files they open fine.

    Kenny



  • 15.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-09-2013 09:40 AM

    Definitely Cryptolocker.  I had the same issue and it turns out the users laptop was taken out of the office sometime after he got infected before the sep scan picked it up and reported to the console.  As soon as he returned and connected it SEP caught it on his machine.  Restored all files in the affected share on the file server from backup and cleaned up his PC.



  • 16.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-09-2013 07:18 PM

    Have a user reporting CryptoLocker.  There is no known recovery for the encrypted files.  Apparently the user did not get a pop-up screen until after the virus had scanned and encrypted all files it found.  The virus will encrypt all user documents both local and found on network drives.

    This user got the screen as shown in the link from the emsisoft.com site below.

    http://www.bleepingcomputer.com/forums/t/506924/cryptolocker-hijack-program/

    http://blog.emsisoft.com/2013/09/10/cryptolocker-a-new-ransomware-variant/

    Does Symantec have a definition set that will detect and block this virus BEFORE it creates damage?

    Note suggestions in the thread on bleepingcomputer regarding blocking .exe files from running from %appdata%\*\

    Follow the link in the 1st post in the bleepingcomputer forum (see link above), then read down from there..



  • 17.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-15-2013 01:37 PM

    F_Mill,

     

    I tried the SysInfoTools but had no such luck.  Do you know of any other software that might recover these files?

    Thanks,

    Jasper



  • 18.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-18-2013 03:55 PM

    Our office has just been hit by this as well. On Oct 17th. No pop ups, no demands for money. The computer was turned on in the morning and all word, excel, pdf files will not open. Just the file format nort recognized problem. Im with Jasper, is there any way to recover the files. The names, extensions, size all appear to be correct. There are thousands of files seemily encrypted. Emsisoft Decrypter did not work in this case.

     

    Thanks.



  • 19.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-23-2013 07:46 AM

    Followers of this thred may be interested in this new blog post from security Response:

    Ransomcrypt: A Thriving Menace
    https://www-secure.symantec.com/connect/blogs/ransomcrypt-thriving-menace

    and also these resources:

    Additional information about Ransomware threats
    http://www.symantec.com/docs/TECH211589
     

    Definitely backup all important data regularly, keep your AV definitions up-to-date, and deploy the IPS component of SEP if you are not already using it!

     



  • 20.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-24-2013 08:40 PM

    Hello Everyone,

    A client just gave me his PC and it was infected with the Crypto Locker Virus.  I was able to remove virus, but it has corrupted all excel, word and PDF files.  But it did try to get money from him.  Luckily he did not fall for this scam.  Unfortunately I can not get to any of his data files except for his pictures.  I will try the SysInfoTools to convert corrupted files and get back to you.  If anyone is able to get their data files fixed, please let me know because the customer did not have a backup.

     

    Thank you



  • 21.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-25-2013 05:27 PM

    I have the seen the same with a few users. No pop ups, no demands, just all .doc, xls, and .pdf files are encrypted say the file format is not correct, etc. 

     

    We think users get this virus via an malicious e-mail. The subject line mentioned something about a 'voicemail' and to open the attachment to listen to the voicemail. 

    I guess there aren't any real fixes for this yet. Total bummer. 



  • 22.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-25-2013 09:12 PM

    I am not sure if this is against the terms of the site to post outside links or not but I just saw this and thought it might apply to the conversation.

    http://nakedsecurity.sophos.com/2013/10/18/cryptolocker-ransomware-see-how-it-works-learn-about-prevention-cleanup-and-recovery/

    Once again, not sure if this violates the terms of the site or not, but I have found this can be a use tool for removing infections for machines, not sure if using this would be a violation of any license agreements either.....

    http://windows.microsoft.com/en-us/windows/what-is-windows-defender-offline



  • 23.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-26-2013 12:34 PM

    We have received two cases this week with the same symptoms but no money ransoms: Word, Excel & PDf files corrupted: The two drives are infected with mabezat worm virus but we know this virus doesn't  corrupt files... so it seems the two cases are linked to cryptolocker virus

    We are trying to recover files: in case of success we will feed you back

    The challenge now is for us=Data Recovery Companies: is anybody able to recover corrupted files?

    Please inform us in case of success!

    Disk & Data Recovery -Algeria



  • 24.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-27-2013 03:56 PM

    We found two interesting links:

    http://malwarefixes.com/remove-cryptolocker-virus/


    http://www.insightsintechnology.com/2012/05/eset-rogue-applications-remover-detects.html#axzz2is0Q8RnU

     

     



  • 25.  RE: Some Virus has corrupted many of our Microsoft Office files and PDF files.

    Posted 10-30-2013 12:57 PM