Restarted my Windows Server the other day, to discover my files locked and a message on my desktop about how they want 1 Bitcoin (~ 590 AUD) to unlock it. I don't use Anti-Virus, because I'm very careful, and haven't had any viruses in my 3 years of doing it. That changes this year.
Lost about 2TB / 8TB of my data, as it only hit one drive, and the boot SSD.
Noticed my friends were asking a tonne of questions, so curious, anyone want to ask anything about it? Just shoot.
and… any progress in debugging?
Have you actually tried using any ransomware removal apps? I know you're somewhat allergic to any sort of antivirus programs but perhaps humble yourself and give Kaspersky a go:
https://noransom.kaspersky.com/