Assistance Required for Ransomware Infection on Azure Windows Virtual Machine

Audit 0 Reputation points
2025-01-28T05:38:08.28+00:00

I think my Azure Windows Virtual Machine has been infected with ransomware. The following issues are observed:

  • IIS and SQL services have stopped and cannot be restarted (error code: -2146893818).
  • All files on the C drive have been converted to .wex format.
  • Attempts to access administrative tools like Server Manager result in errors.

Please assist in identifying the infection source, recovering the virtual machine, and securing it against future attacks.

This is the exact message i am getting when i start iis, sql or any other services -
--------------------------- Services --------------------------- Windows could not start the IIS Admin Service on the Computer. For more information, review the System Event Log. If this is a non-Microsoft service, contact the service vendor, and refer to service-specific error code -2146893818. --------------------------- OK    ---------------------------

  [Window Title] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Server Manager.lnk [Content] Windows cannot find 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Server Manager.lnk'. Make sure you typed the name correctly, and then try again. [OK]

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
8,298 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.