Home › Forums › BulletProof Security Free › MY Server got encrypted with some ransomware known to be Akira (.akira)
- This topic has 10 replies, 2 voices, and was last updated 1 day, 4 hours ago by
AITpro Admin.
-
AuthorPosts
-
Dr Aspain
ParticipantHello, I am sorry to post this here. I am trying to post on public forums for help. I am doctor by profession and recently my server got infected by a virus known as Akira ransomware. All files are ending with .akira extension. I am unable to access anything and seemed to be corrupted. The data is really important for me as it contains important research papers and my patient’s history.
Note: I have already tested public decryptors like Avast Akira Decryptor. It did not workAITpro Admin
KeymasterDo you have a Windows or Linux server? Is the server inhouse or offsite?
AITpro Admin
KeymasterMy first thought was to boot into Linux from a Linux boot disk (Hiren’s BootCD PE). This is the method that these guys (DIRT) used on a VMware ESXi server > https://medium.com/@DCSO_CyTec/unransomware-from-zero-to-full-recovery-in-a-blink-8a47dd031df3
AITpro Admin
KeymasterJust checked your IP address and it has a high threat level. That could mean that you are a bad actor or your computer/network is compromised and your IP address is seen as an attack vector IP.
ThreatLevel: “high”: An IP address with a “high” threat level is an immediate and serious security risk. This is not a vague or minor threat but one that requires urgent attention and protective measures.
Dr Aspain
ParticipantMy server is windows
Dr Aspain
ParticipantWhat to do for this?
AITpro Admin
KeymasterTry these guys > https://www.ransomwarehelp.com/. They are BBB accredited, have good reviews and claim that if they cannot recover your data you pay nothing. Important Note: Ransomware Help has zero reviews on Trustpilot.
AITpro Admin
KeymasterTrying to figure out which variant of Akira your server is infected with and then figuring out the encryption method would be very difficult unless you are very familiar with ransomware decryption. So yeah definitely go with a Pro.
Dr Aspain
ParticipantThey are very expensive + don’t seem legit to me.
AITpro Admin
KeymasterHmm they appear to be legit to me. In any case, I’m not a computer/network server ransomware specialist. My area of expertise is website security, which includes web servers and websites. Do google searches for “Akira ransomware recovery” and be sure to check BBB and reviews for any possible companies that you find.
AITpro Admin
KeymasterProven Data looks good > https://www.provendata.com/. They have excellent Trustpilot reviews. They have an F rating on BBB, but I looked at one of the complaints and it is ridiculous or spam. They have been in business for 16 years and only have 2 complaints on BBB. That is exceptional.
-
AuthorPosts
- You must be logged in to reply to this topic.