LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Programming (https://www.linuxquestions.org/questions/programming-9/)
-   -   Virus did corrupt all pictures on computer (https://www.linuxquestions.org/questions/programming-9/virus-did-corrupt-all-pictures-on-computer-4175545802/)

Haroun 06-19-2015 02:51 AM

Virus did corrupt all pictures on computer
 
Hi,

I am not sure this is the right thread. A kind of virus did corrupt all pictures on a friend's windows based computer. All jpg files won't open any more. He told me some ads were asking for money to retrieve them all.

I took a jpg on my mac which i can't open either. Jpg files still seem to have coherent sizes.

Link removed (warning: may infect your PC if under windows i believe).
Any help would be appreciated to recover the picture (or hint where to get help). With the process i would be able to recover all my friend's pictures.

Regards,
Haroun

ButterflyMelissa 06-19-2015 02:59 AM

are you using windows?
Okay, maybe a simple approach: get a live CD, start up with that, mount the hard drive, mount a USB stick, copy n paste the pictures. Chances are not the pictures are infected but the system to open them...read (tadaaaa) windows itself....
My thought: infecting ALL the pictures (individually) takes time, and that could be a give away...
listening on...
Thor
PS - if you are using ***dows...consider THIS a fork in the road to switch to Linux...we'll help you find the right distro :)

Haroun 06-19-2015 03:10 AM

Hi Thor,

My friend uses ***dows as you say :-) I use mac os on my end

I took his pictures to my mac which can't open them either (true that the copy paste was not made from a CD startup)

Can i somehow send a sample corrupted jpg to see if you can find a way to open it ?

Haroun

Haroun 06-19-2015 03:21 AM

Link removed

astrogeek 06-19-2015 03:36 AM

Let's see, an infected window$ machine and a friend with a Mac helping out by posting possibly infected files to a Linux forum...

First, please do not link those from this forum - please remove the links.

Next, please seek help in a window$ forum to identify and fix the window$ problems.

If your friend wants to switch to Linux, this would be the right place.

Haroun 06-19-2015 03:40 AM

Hi,

I removed the links. I am just trying to get help from the best guys, thus Linux guys :)

Haroun

astrogeek 06-19-2015 03:46 AM

Thank you for removing the links.

In order to recover the images it will be necessary to identify how they have been corrupted or encrypted, and that is entirely a window$ related question.

If you can find out more information about what has happened to those files and re-ask a more specific question with some suppporting information someone would be able to help.

Good luck!

Haroun 06-19-2015 03:52 AM

Ok thanks! Do you know a good window$ forum that could help out ?

sundialsvcs 06-19-2015 07:15 AM

One thing that I'm curious about: how do you know that these image-files have been corrupted by malware?

How do you know that they are not simply ... damaged?

Haroun 06-19-2015 07:46 AM

My friend had a pop-up asking for money to get access back to his pictures...

michaelk 06-19-2015 08:31 AM

It appears that your friends computer was infected by cryptolocker malware. The files are encrypted and impossible to recover.

The virus can be removed but the files are lost unless you have a backup. I suggest using malwarebytes software.

schneidz 06-19-2015 08:31 AM

i think if its like the fbi moneypak virus i think the criminals encrypt the files on your pc and hold a ransom for the keys.

if so i dont think it would be practical to be able to get access back (i wouldnt pay the ransom because they are probably bluffing).

what happens when you run the file command:
Code:

[schneidz@hyper photos]$ file dscf0171.jpg
dscf0171.jpg: JPEG image data, JFIF standard 1.01


michaelk 06-19-2015 08:36 AM

I agree, as far as I know the criminals have the keys and no guarantees that if you pay they will honor their terms.

bathory 06-19-2015 08:47 AM

Quote:

Originally Posted by michaelk (Post 5379801)
It appears that your friends computer was infected by cryptolocker malware. The files are encrypted and impossible to recover.

The virus can be removed but the files are lost unless you have a backup. I suggest using malwarebytes software.

Maybe this worth giving a try

Haroun 06-19-2015 09:31 AM

Schneidz, it gives:
Code:

haroun$ file 858HDJES.jpg
858HDJES.jpg: data

Bathory, i tried this and it told me it is not a crypto locker infected file... I should probably try to find equivalents. It seems unlike crypto locker, only jpg files were affected (word documents were unharmed for instance)


All times are GMT -5. The time now is 12:49 AM.