LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > Programming
User Name
Password
Programming This forum is for all programming questions.
The question does not have to be directly related to Linux and any language is fair game.

Notices


Reply
  Search this Thread
Old 06-19-2015, 10:12 AM   #16
firstfire
Member
 
Registered: Mar 2006
Location: Ekaterinburg, Russia
Distribution: Debian, Ubuntu
Posts: 709

Rep: Reputation: 428Reputation: 428Reputation: 428Reputation: 428Reputation: 428

Hi.

Maybe there are unaffected copies of some jpegs on other medium? In this case you could try to compare before- and after- states and try to figure out the algorithm. Maybe just a couple of bytes are changed or files are XOR'ed with something (you can try to use known JPEG headers to figure out the key).

Just guessing.
 
Old 06-19-2015, 11:08 AM   #17
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Check out https://bitbucket.org/jadacyrus/rans...alkit/overview
 
Old 06-19-2015, 01:05 PM   #18
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
As they say they received a popup asking for payment, it would indeed appear to be some cryptolocker type of exploit.

On the other hand, you say it is only jpg image files that are affected, and your original links were to a goodle drive account (thanks again for removing them so quickly) - so I wonder if it is related to the problem discussed in this thread.
 
Old 06-19-2015, 02:56 PM   #19
Haroun
LQ Newbie
 
Registered: Jun 2015
Posts: 10

Original Poster
Rep: Reputation: Disabled
Firstfire, I will check with my friend if we can find a photo that we can compare.
Habitual, will check this as soon as I have access to my computer!
Astrogeek, I don't think it is related: jpg files infected were local on my friends pc (he also corrupted his back-up hard drive when he plugged it on his machine). I just uploaded an example of corrupt jpg on my google drive so that people could try to detect what's wrong with the file or attempt to fix it, knowing it does cause any issue on non win**** systems (tried on my mac :-))

Thank you all for giving advice: I didn't expect so many useful answers, somehow I knew I was turning myself to the best !
 
Old 06-19-2015, 03:41 PM   #20
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
IF you can upload one of those suspect file to virustotal.com, you may just a clue about these anomalous files.
 
Old 06-22-2015, 04:12 AM   #21
Haroun
LQ Newbie
 
Registered: Jun 2015
Posts: 10

Original Poster
Rep: Reputation: Disabled
Hi,

A little update:
- virustotal didn't find anything weird about my file
- my friend will look if he can find a non corrupted version of one file to see if we can compare data contained
- his office documents were infected too (must have been tired when he explained in the first place)

- it seems he was infected by "threat finder v3", need to see if i can find more details about that (it does not seem to be included in the ransomware removal kit you provided, Habitual)

Haroun
 
Old 06-22-2015, 04:24 AM   #22
Haroun
LQ Newbie
 
Registered: Jun 2015
Posts: 10

Original Poster
Rep: Reputation: Disabled
PS: it seems files can be recovered with the system restore tool sometimes, will give it a try !
 
Old 06-26-2015, 01:54 AM   #23
Ranamon
Member
 
Registered: Feb 2013
Location: Land of Hopenchange
Distribution: Slackware
Posts: 45

Rep: Reputation: Disabled
This is "ransom-ware" and is one very good reason to keep Win-doesn't anti-virus soft up to date. Backup everything, preferably to a write once CD or DVD, that you want to keep.

Even better, ditch Win-d'ohs completely.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Some Funny Linux/Computer Pictures LXer Syndicated Linux News 0 05-23-2009 03:40 PM
Post pictures of your computer. IanPappas General 1 10-13-2005 05:37 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > Programming

All times are GMT -5. The time now is 12:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration