Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


How to restore server after Ransomware attack?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

How to restore server after Ransomware attack?

serversupportzserversupportz Member, Host Rep

Hello guys,can any server experts suggest what can be done in these situations to restore the site?

Comments

  • NeoonNeoon Community Contributor, Veteran

    Backups, but they are rare in such cases.

    Thanked by 1sanvit
  • FAT32FAT32 Administrator, Deal Compiler Extraordinaire
    edited March 2019

    There is nothing much you can do now if it is a new ransomware. My suggestion is as follow:

    1) Complete backup of your server in another machine
    2) Wait until someone found the decryption key

    At least you still have a chance to retrieve the data back few months to years later. Don't just format it without backup thinking it is impossible.

    Moreover, most ransomware only encrypt the first X% of the files. If some of your files are raw (Text files, logs, raw images...), you still can retrieve part of the data.

  • deankdeank Member, Troll

    Join Nigh sect.

    Or just format to FAT32.

  • oneilonlineoneilonline Member, Host Rep

    Is this a local server or in a datacenter? Consult with your provider if its hosted. Hope you have backups!

  • AmitzAmitz Member
    edited March 2019

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

  • deankdeank Member, Troll

    I believe OP is building a knowledge base based on replies on LET. I know some dude (that got banned before) was doing it.

  • @deank said:
    I believe OP is building a knowledge base based on replies on LET. I know some dude (that got banned before) was doing it.

    I think you are right. Either that or OP is offering server support(z) to clients and asking for a friend

  • @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    Welcome back mate :)

    Thanked by 1Amitz
  • deankdeank Member, Troll

    People generally run a business on a subject they are well versed in.

    Hosting industry seems to be the opposite.

    Thanked by 2Razza Shot2
  • RazzaRazza Member

    @deank said:
    People generally run a business on a subject they are well versed in.

    Hosting industry seems to be the opposite.

    I think it due to hosting business are quite easy business to set up, it only when there issue that need fixed is when the near zero experience of the owner become apparent.

  • And yet they still didn't fix their login page...

    @teamacc

  • deankdeank Member, Troll

    I once tagged @teamaccc so frequently that he gave me a warning.

    Good old times.

    Thanked by 1Amitz
  • angstromangstrom Moderator

    @sanvit said:
    And yet they still didn't fix their login page...

    @teamacc

    The OP doesn't care.

    It's easier for them to start meaningless threads on LET than to fix their login page.

  • sanvitsanvit Member
    edited March 2019

    @angstrom said:

    @sanvit said:
    And yet they still didn't fix their login page...

    @teamacc

    The OP doesn't care.

    It's easier for them to start meaningless threads on LET than to fix their login page.

    If they don't care about what the mods say... @deank

    This was on his last thread

  • deankdeank Member, Troll

    The end is nigh.

  • @serversupportz said:

    Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    It is simpler than what you think, just pay the hacker the ransom.

    Thanked by 2Adam1 dahartigan
  • deankdeank Member, Troll

    And then get ransomed few days later again.

  • @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    Thanked by 1Amitz
  • @doghouch said:

    @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    I think @Amitz was being sarcastic ;)

    Thanked by 1Amitz
  • @dahartigan said:

    @doghouch said:

    @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    I think @Amitz was being sarcastic ;)

    I think @doghouch was being sarcastic too ;)

    Thanked by 2Amitz doghouch
  • @sanvit said:

    @dahartigan said:

    @doghouch said:

    @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    I think @Amitz was being sarcastic ;)

    I think @doghouch was being sarcastic too ;)

    Maybe I was being sarcastic too ;)

    Thanked by 2sanvit Amitz
  • @dahartigan said:

    @sanvit said:

    @dahartigan said:

    @doghouch said:

    @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    I think @Amitz was being sarcastic ;)

    I think @doghouch was being sarcastic too ;)

    Maybe I was being sarcastic too ;)

    In that case, I was being sarcastic too ;)

    Thanked by 1Amitz
  • @sanvit said:

    @dahartigan said:

    @sanvit said:

    @dahartigan said:

    @doghouch said:

    @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    I think @Amitz was being sarcastic ;)

    I think @doghouch was being sarcastic too ;)

    Maybe I was being sarcastic too ;)

    In that case, I was being sarcastic too ;)

    lol I think we have some recursive sarcasm going on here.. ;)

    Thanked by 2sanvit Amitz
  • @dahartigan said:

    @sanvit said:

    @dahartigan said:

    @sanvit said:

    @dahartigan said:

    @doghouch said:

    @Amitz said:

    serversupportz said: Hello guys,can any server experts suggest what can be done in these situations to restore the site?

    I would post on LET and ask there. That is what all professionals do.

    But why? He runs a ‘24/7 emergency hotline’ that fixes these exact problems.

    I think @Amitz was being sarcastic ;)

    I think @doghouch was being sarcastic too ;)

    Maybe I was being sarcastic too ;)

    In that case, I was being sarcastic too ;)

    lol I think we have some recursive sarcasm going on here.. ;)

    I think I stack overflowed from sarcasm.

  • Use two fingers first.

    Thanked by 1Amitz
  • You don't.
    Nuke the filesystem and boot sector from Orbit. Then, restore from backups onto a secured fresh OS install.

    Sorry to say this, but If you have to learn this lesson, make sure you don't learn it more than once.

    Thanked by 1Amitz
  • @deank said:
    Join Nigh sect.

    Or just format to FAT32.

    I keep my TempleOS images on a ReiserFS partition.

Sign In or Register to comment.