Skip to main content

Most of backups were suddenly deleted.

Thread needs solution

Today most of my backups were suddenly deleted from local drive. I didn`t delete them by myself and don`t know what else could did it.

0 Users found this helpful

There seems to have been a few similar reports in the forums over recent days with no obvious reason apparent for why?

If you have ATI 2020 latest build 22510 then please either open a support case direct with Acronis or else submit Feedback to them along with an Acronis System Report and link to this forum topic, so that they can investigate what is going on?

If you want to send me a private message with a link to download the System Report zip file via a cloud service such as OneDrive etc, then I will take a look to see if I can see what has happened, if anything is shown in the ATI logs?

Was it just your backup (.tib or .tibx) files that were deleted or was it also the backup tasks in the GUI deleted too?  How did you notice that they were all gone?

I`d like to investigate ATI logs by myself. Where I can find them?

Only backups were removed. The task still exist but ofc ATI can`t find the tibx-files.  It was very easy to noticed this for me when I saw that I`ve got a lot of free space on HDD(About 200-300GB). Only deleting tibx-files could release so much space.

Please download the MVP Log Viewer tool (link in my signature below) and use this to review the log file for your backup operation. This should provide more information on what is happening.

Note: ATI 2020 now uses backup_worker logs for the more detailed messages for .tibx tasks and these are not shown by the MVP log tool - you can find these in the C:\ProgramData\Acronis\TrueImageHome\Logs\backup_worker folder and open them in Notepad.

MVP log tool find very old logs.

backup_worker  has some logs for that time but there no helpful information:

2020-03-13T17:12:12:627+03:00 6472 I00000000: >>> --id=10002 --action=metainfo --agent="Acronis True Image 2020 24.5.1.22510 Win" --archive="D:\\backup\\SanDisk SD8SNAT128G1002 Z2317002.tibx"
2020-03-13T17:12:12:756+03:00 14008 I00000000: type=log; level=inf; message=ar#1: opening archive path="\\?\D:\backup\/SanDisk SD8SNAT128G1002 Z2317002.tibx" in readonly mode;

2020-03-13T17:12:12:758+03:00 14008 I00000000: type=log; level=err; message=io: failed to open '\\?\D:\backup\SanDisk SD8SNAT128G1002 Z2317002.tibx' (win_err=-2);

2020-03-13T17:12:12:758+03:00 14008 I00000000: type=log; level=err; message=io#1: failed to open "\\?\D:\backup\/SanDisk SD8SNAT128G1002 Z2317002.tibx" (pcs_err=-8);

2020-03-13T17:12:12:758+03:00 14008 I00000000: type=log; level=err; message=ar#1: failed to open archive path="\\?\D:\backup\/SanDisk SD8SNAT128G1002 Z2317002.tibx" mode=readonly uuid=00000000000000000000000000000000, err=-5022 (File not found);

2020-03-13T17:12:12:758+03:00 14008 I00000000: type=log; level=err; message=unable to open archive file (err -5022);

2020-03-13T17:12:12:759+03:00 14008 I00000000: type=retcode; value=5022; id=10002;

2020-03-13T17:12:12:764+03:00 6472 I00000000: >>> exit

Stanisluv, can you check the MMS logs on your computer to see if that mentions anything being deleted?  Another user is in the process of reporting a similar issue and found evidence in his MMS logs of backups being deleted? (The new topic is waiting on moderation before it will appear in the 2020 forum).

Nothing in MMS logs too. Also it seems like files were "shredded" because 3rd party recovery software can`t find them in deleted files. So there no footprint for them in MFT.

Ok, that is strange and sound more like malware / ransomware type activity but really needs to be investigated by Acronis to determine exactly what has happened and why?

The other topic has now appeared in the 2020 forum: Acronis True Image 2020 - gone berserk and deleted everything

Were any files other than ATI backup files missing?  Per Steve's comment about malware / ransomware, it seems unlikely that malware would target only ATI files unless it was malware that specifically targeted backup files.

What kind of drive contained the files?  NAS?  An external USB or SATA drive?  Is it a hard drive or an SSD?

I'm pretty sure that ATI does nothing more than just a typical file delete when it gets rid of backups.  If your files have really been "shredded" , it sounds like something other than ATI did it.  (There is a "DriveCleanser" utility in ATI that might do more than just a delete, but I've never used it.) 

BTW, I've heard that 3rd party data recovery tools have a harder time recovering deleted files from SSDs than HDDs. 

I`m not sure about other files (there so much of them) but seems like only tibx-files were deleted and this is happened on separate HDD (no NAS, no external drive or smth similar ).

 

Best Regards,

Stan.

Stan, was this on a single HDD or did it affect more than one drive?

Have you run a CHKDSK /F for the HDD?

Single HDD. I don`t want to do checkdisk for now because I hope there is a chance to restore this backups with 3rd party software. Anyway It`s weird behavior. All I did before was download antivirus installed on that drive and then I noticed huge changes in free space. Also 1-2 tibx-files still there but seems like they are already corrupted. At least I can`t add them to ATIH

Check if your new antivirus has any logs to show any actions it has taken?  You can also just run CHKDSK without any switch parameters such as /F to get a report without correcting any issues being identified.

There is no new AV. I just downloaded installer for future reinstall. Anyway nothing in AV logs and I already made simple chkdsk in Windows-no error too.

I think I found smth. Looks like it related to Tib Mounter Service. I found 1 error in Event Viewer in exact time when all backups gone:

 

 <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

<System>
  <Provider Name="Tib Mounter Service" />
  <EventID Qualifiers="0">0</EventID>
  <Level>4</Level>
  <Task>0</Task>
  <Keywords>0x80000000000000</Keywords>
  <TimeCreated SystemTime="2020-03-13T14:10:02.021728900Z" />
  <EventRecordID>11666</EventRecordID>
  <Channel>Application</Channel>
  <Computer>DESKTOP</Computer>
  <Security />
  </System>
<EventData>
  <Data>Service started/resumed</Data>
  </EventData>
  </Event>

Stan, there should be no reason why the TibMounter Service would be involved in deleting any backup files.  This service only has one real purpose which is to monitor for any requests from the user to mount a .tib file to a Windows drive letter.  This only applies in ATI 2020 to Disks & Partitions backups created by earlier versions & continued by 2020 using .tib file format.  There is no current mount option provided for the new .tibx file format, which is a known limitation complained about to Acronis lots of times.

I see. Anyway there no backups on HDD and I`m fold for now. May be full check disk incl surface check will find smth.

Windows has scanned the file system and found no problems.
No further action is required.

Sad and it`s bad for me. :(

Stan, out of interest, check the pcs.0.log for any errors being reported - this is found in the same folder as the ti_demon logs.

Negative. There are 2 latest strings from this log:

2020-02-06T15:12:29:198+03:00 18840 I00000000: file_filter_add_mask(mask='C:/WINDOWS/CSC', mask_kind=FF_MASK_EXCLUDE, mask_type=FF_MASK_WILDCARDS)
2020-02-06T15:12:29:198+03:00 18840 I00000000: file_filter_add_mask(mask='*/System Volume Information/*{3808876B-C176-4e48-B7AE-04046E6CC752}', mask_kind=FF_MASK_EXCLUDE, mask_type=FF_MASK_WILDCARDS)