Solved

Server 2008 R2 Image Restore to Dell Perc H710

Posted on 2016-08-27
15
184 Views
Last Modified: 2016-11-22
I have a Dell PowerEdge T320 running Windows Server 2008 R2 with a Perc H710 in RAID 1 that got hit with ransomware.   I wanted to restore a clean image that was created with Active@ Disk Image.   Using Active@ Boot Disk the restore completed successfully.    Upon booting up I get a "Windows failed to start......Status:   0xc000000e   Info:  The boot selection failed because a required device is inaccessible."  

I restarted the computer with the Server 2008 R2 DVD and clicked "Repair Your Computer".   No operating system was listed so I continued on to the command prompt.   Under X:\Sources I tried running bcdedit but the file was not found.   I then tried x:\sources\recovery\StartRep.exe but that was unable to repair.   I then ran DISKPART> List vol and the only volume that was found was the DVD

I rebooted the server using Active@ Boot Disk and opened a command prompt.   From there I was able to see all of my data including:

C:  Recover
D:  Datapart2
E:  Datapart
F:  OS
G:  DVD

I am assuming that all I need to do is repair the bootmgr so windows knows where to find the OS, but I am lost as to how.
0
Comment
Question by:rpmaps
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
  • 3
  • +1
15 Comments
 

Author Comment

by:rpmaps
ID: 41772946
Follow Up:    

Under system recovery options I loaded the drivers for the Perc H710 and was able to find my Windows Server 2008 R2 under (H:) OS.   I was then able to run x:\sources\bcdedit.   It listed my Boot Manager as partition =F: and Boot Loader as partition=H:

I then ran x:\sources\recovery\StartRep.exe but again was told that Windows could not repair this computer automatically
0
 
LVL 79

Expert Comment

by:arnold
ID: 41773401
Do you have a boot on c:\
You need to both use bcdedit and bootrec to reconstruct the boot.
Is the system configured as uefi boot or bios boot? If uefi double check it points to ...

Check the perc config to make sure the disks on which the OS is marked as the boot volume.
0
 
LVL 21

Expert Comment

by:Radhakrishnan R
ID: 41773515
Hi,
If I was in your situation,  I'll do this.
I believe you have full backup?
Install the os as fresh, restore the data.
0
Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

 
LVL 43

Assisted Solution

by:Davis McCarn
Davis McCarn earned 250 total points
ID: 41773651
Because that Dell is from 2014, it's almost a surety that it uses UEFI and what I did not see listed is the EFI System Partition which is where the initial boot occurred.
Active@DiskImage should have been used with the option to create an image of the Physical drive rather than a logical partition and I suspect it wasn't or it wasn't restored properly.  Go back and check! If you have the option to restore the drive, you'll be able to select it and you'll have to take all of it.  If you don't have the option, you'll have to delete all of the partitions in the Server 2008 setup and let it recreate the partitions it needs by clicking next.  Once you have seen it boot and work, you can restore the OS partition and using startup repair from the installation DVD should put you back in business.
If you need more help, I need to know the name of the Ransomware that got you in the first place.
0
 

Author Comment

by:rpmaps
ID: 41773819
Davis:   What I have is a "hidden" OEMDRV which contains BCRaidInject.vbs.   Is this the EFI System Partition?
Active@DiskImage had been setup to do a full Disk to Image backup which included all physical drives and partitions.  When I did the restore, I did a complete Image to Disk which included all drives and partitions, keeping them the same size and location.     After the restore I used the explorer contained in Active@Boot and was able to see all of the drives/files/folders but the computer wouldn't boot.

Since my original post, upon advice from Dell Pro Enterprise Support, using the Dell Lifecycle Controller I installed a fresh copy of Server 2008 R2 onto the OS partition leaving other partitions intact.   The server successfully rebooted to the new OS.   I could see that my original data partitions were still intact.   Now that the computer was properly booting the the OS, I used Active@DiskImage to restore ONLY the OS partition.     That brought me back to square 1 with a system that would not boot.

As I sit here at 1:02 PM (Eastern) I have again reinstalled a fresh copy of Server 2008 R2 and was expecting to rebuild it from scratch with AD, DNS etc...and reinstall all of my programs.    I NEED to have this system up and running by this evening as the office expects a busy day tomorrow.    If you can walk me through a possible solution which would save me the trouble of the rebuild, I would be grateful.
0
 

Author Comment

by:rpmaps
ID: 41773833
Under system setup  Boot Mode is handled by BIOS.   It further states that the two virtual drives are handled by BIOS.   The H710 Configuration Utility lists the State as Optimal
0
 
LVL 43

Expert Comment

by:Davis McCarn
ID: 41773837
Did you try running startup repair from the server 2008 installation disc after you restored the OS partition?
0
 

Author Comment

by:rpmaps
ID: 41773844
YES....same results:   Could not repair automatically
0
 
LVL 79

Expert Comment

by:arnold
ID: 41773897
What does the system do, functions?
Some applications do not support imaging, unfortunately, it seems prior to the current attempts, you've not checked whether the i aging/restore work.

Are you able to reinstall the applications on the reinstalled OS, and restore from image just the data?

Bootrec/bcdedit in combination restore booting along with active bit on the first(boot drive)

The difficulty, usually the OS is on C: it will run on another, but often the /boot will be on the primary boot drive which might correspond with the volume where c:\ partition is.

How certain are you that the image is pre-ransomeware compromise?
Do you have other backup of data using Windows backup
Try restoring the other partitions from image.
0
 

Author Comment

by:rpmaps
ID: 41773958
I have been able to do successful Active@Disk Image restores to other Dell servers with RAID 1, but this is my first attempt with the Perc H710

What I am doing now is just as you were describing:   With the reinstalled OS, I have reconfigured my features and roles and am now reinstalling my applications.   I will then import my data


The ransomeware was ZEPTO.    At 8:41AM and email came to the receptionist with an attachment for a voice mail.   When she couldn't open it on her workstation she asked another employee to try it on her workstation.   The 2nd workstation opened it 8:43AM.     Every application they used since that point had scattered ZEPTO files including files they accessed from the server.    All ZEPTO files had a date stamp of 8:41 and 8:43.   Since it also affected files on the servers OS partition under Program Files (x86) I felt that it would be best to start with a fresh backup.   The backup that I was using was from the previous night.
0
 
LVL 79

Accepted Solution

by:
arnold earned 250 total points
ID: 41773987
I've not, but restoring a partition at a time versus enmass might yield better results as it may provide for a faster attempt as well as directing the restoration ...............

Seen situation where whole backup comingels intertwined... Where an individual fare better.
Presumably you have several logical volumes when restoring, do you gave an option to specify which partition's image will be written on which volume?/partition?
0
 
LVL 43

Expert Comment

by:Davis McCarn
ID: 41773990
Zepto is a derivative of Locky and encrypts:

Office/Document files (62x): .123, .602, .CSV, .dif, .DOC, .docb, .docm, .docx, .DOT, .dotm, .dotx, .hwp, .mml, .odg, .odp, .ods, .odt, .otg, .otp, .ots, .ott, .pdf, .pot, .potm, .potx, .ppam, .pps, .ppsm, .ppsx, .PPT, .pptm, .pptx, .RTF, .sldm, .sldx, .slk, .stc, .std, .sti, .stw, .sxc, .sxd, .sxi, .sxm, .sxw, .txt, .uop, .uot, .wb2, .wk1, .wks, .xlc, .xlm, .XLS, .xlsb, .xlsm, .xlsx, .xlt, .xltm, .xltx, .xlw, .xml
 
Scripts/Source codes (23x):
.asm, .asp, .bat, .brd, .c, .class, .cmd, .cpp, .cs, .dch, .dip, .h, .jar, .java, .js, .pas, .php, .pl, .rb, .sch, .sh, .vb, .vbs
 

Media files (20x):
.3g2, .3gp, .asf, .avi, .fla, .flv, .m3u, .m4u, .mid, .mkv, .mov, .mp3, .mp4, .mpeg, .mpg, .swf, .vob, .wav, .wma, .wmv
 

Graphic/Image files (14x):
.bmp, .cgm, .djv, .djvu, .gif, .jpeg, .jpg, .NEF, .png, .psd, .raw, .svg, .tif, .tiff
 

Database files (14x):
 .db, .dbf, .frm, .ibd, .ldf, .mdb, .mdf, .MYD, .MYI, .odb, .onenotec2, .sql, .SQLITE3, .SQLITEDB
 

Archives (11x):
 .7z, .ARC, .bak, .gz, .PAQ, .rar, .tar, .bz2, .tbk, .tgz, .zip
 

CAD/CAM/3D files (8x):
 .3dm, .3ds, .asc, .lay, .lay6, .max, .ms11, .ms11 (Security copy)
 

Certificates (5x):
 .crt, .csr, .key, .p12, .pem
 

Virtual HDD (4x):
 .qcow2, .vdi, .vmdk, .vmx
 

Data encryption (2x):
 .aes, .gpg
 

Virtual currency (1x):
 wallet.dat
 
But; unless folks were RDP'ing into the server with high level privileges, the files in C:\Program Files on the server should not have been affected.  This makes me think that that "previous night's" backup was already infected, somehow, and may be the source of your problem.
Supposedly, Disk Image will let you inspect the contents of it's backups.  Have you checked to see there is no evidence of ZEPTO in the backup you are restoring?  Or, did you think of trying the night before?
0
 
LVL 43

Expert Comment

by:Davis McCarn
ID: 41773991
P.S. The PERC controller, IMHO, has nothing to do with the problem unless it needs special drivers loaded, in which case, you need to load them before you try startup repair.
0
 

Author Comment

by:rpmaps
ID: 41774093
There was no RPD'ing and they users are under Domain Users privileges .   The particular Program Files (x86) folder was not even shared which surprised me that it was hit.  The program was PowerPay which resides on the server but is integrated into practice management software.

I did explore the image file and there were no signs of ZEPTO files.
0
 

Author Comment

by:rpmaps
ID: 41774231
Arnold:  You may be onto something there.  It seems that with so many partitions being restored Windows didn't know where to go for the OS.   That is where I was hoping the Startup Repair would have come in.     Since I was restoring to the same hard drive configuration, I thought it would be best to do one restore with options to restore to the same location with same partition sizes.  Next time (hopefully not soon) I will try a more targeted restoration.

Bottom line:   After a full weekend blown, the server is up and running with a fresh OS and Applications.  Good news is no data was lost.  

Thanks for all of the input.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
In 2017, ransomware will become so virulent and widespread that if you aren’t a victim yourself, you will know someone who is.
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question