I have customer server that was recently infected with Ransomeware. Long story short I had a tech that was restoring the files and folders but instead restored the C and D drives corrupting the server so that I had to do a bare metal restore.
I have everything working again and data restored before the infection happened but now when I look at my Administrative Tools I see two entries for each one from the Server Manager . One normal as you would expect and the other with a .lnk~ with a random number after it. I looked in System32 and see two of each but these have DLL~ random number on the second one.
I'm not seeing much information on the web about this so I was hoping someone could let me know if I can delete these or if I have a bigger issue.
The server is a Windows 2012 Essentials server.