Ransomwared :-(

I’ve moved this thread into a support area. Everyone that is not @Aleksei_Domanin – please try to stay out of this until we have some more information and time to investigate.

3 Likes

I edit and add albums via network folders \192.168.1.9\Data
There I saw text files !0XXX_DECRYPTION_README.TXT
I probably didn’t write correctly. Encrypted all 12600 album covers, all text files and log files in Roon Сore operating system. Flaс and dsd did not suffer
And yes, I have a backup.

P.S. for Firewall # FortiGate Mid-Range
(Next Generation Firewall (NGFW) - See Top Products)

What is your 192.168.1.9 machine? Your ROCK seems to be at .7.

Where is this 12tb drive now?

Yes, of course, at the end of “7” it was all too late and I was already typing without glasses, also through a translator.
Now the disks are connected to the intel nuc. To be exact, these are 3 external hard drives; 1 WD 4tb, Verbatim 2 pieces of 4tb. As I already wrote, the software on the intel nuc was reinstalled.
on the disks using the search, I found all the files with the extension “0xxx”, which is about 70 GB (These are album covers) and deleted them.
I have already begun to restore something, you can get the album cover from the track and save it separately again in the folder of each album, but you yourself understand >12600 times you need to do this :frowning: + restore other pictures of the “artist”

What else is on your network? It sounds like your have something installed on your network and that thing is encrypting your files. It could happen again if you don’t remove the offensive element

1 Like

I will check my computer, “Windows” and MacMini, I will need some time. there is confidence that the Mac is not to blame, it costs a month in standby mode “asleep”, it remains to check the PC. There are also a lot of files and they are now in order.

This topic was automatically closed 45 days after the last reply. New replies are no longer allowed.