Aller au contenu principal

Acronis True Image 2020 - gone berserk and deleted everything

Thread needs solution

I have no hyperlinks inside text, but it still shows "You are not allowed to place hyperlinks inside the text, please, clear them." It took a while to post it.

True Image 2020 v22510

I’m using Acronis since 2017 version, yesterday has happened the MAJOR flip up. I have opened explorer to watch a movie, when noticed, that disk with backups has suspiciously much free space. Opened it to check up and my heart almost stopped and hair became nearly white. It was empty.

Completely clean

Zero backups

Nothing

Everything gone

Opened TI, from 8 schedules (5 local 3 cloud) 6 gone (5 local 1 cloud). I have no logical idea how that has happened, like someone remotely deleted 6 schedules with files. I remembered the last case, that happened in autumn 2019 all schedule settings messed up and reset, I even remember you have acknowledged it in blog or somewhere else (kb.acronis.com-content-63819).

In the end, what I got from logs (kb.acronis.com-content-59335). Log type: MMS full of errors

"Time": 00 13444 E00000000: Failed to match task type 5 for task "A"

"Time": 00 13444 E00000000: Failed to match task type 5 for task "B"

"Time": 00 13444 E00000000: Failed to match task type 5 for task "C"

"Time": 00 13444 E00000000: Failed to match task type 5 for task "D"

"Time": 00 13444 E00000000: Failed to match task type 5 for task "E"

Real data replaced with "A-E" intentionally, also as "Time" for security reasons. They repeat itself every 60 seconds, same 5 strings. Later I found:

"Time": 00 17956 I0135003A: User '' (clientProfileID=''; clientSessionID='') is running command 'TODO: Fix command name for CommandID = "A"'.

"Time": 00 17956 I01900000: Deletion of online backup "A" has started.

"Time": 00 17956 I0135003B: Command 'TODO: Fix command name for CommandID = "A"' has completed successfully.

This repeated for every backup (8 in total), in a minute everything was deleted, except 2 survivors, just few hours before I "went" to watch film.

I have no idea will brick hit the face again in the future, so I disabled Acronis Managed Machine Service Mini in services and made a rule for antivirus software to block any network activity for mms_mini.exe. I think someone intentionally or not passed a command for deletion of ALL backups on my PC from remote dashboard via Acronis MMS. I didn't use it even once. Will sleep better at night, knowing that this dangerous hole dug for good.

If you are reading it, go and check your backups NOW. I hope that's not a widespread error.

0 Users found this helpful

Mr Keks, welcome to these public User Forums.

Please see forum topic: Most of backups were suddenly deleted. for cross-reference.

As you have ATI 2020 latest build 22510 then please either open a support case direct with Acronis or else submit Feedback to them along with an Acronis System Report and link to this forum topic, so that they can investigate what is going on?

If you want to send me a private message with a link to download the System Report zip file via a cloud service such as OneDrive etc, then I will review the ATI logs?

Do you have any offline / disconnected backups you can use if needed?

Thank you for your answer and cross-reference suggestion.

Yes, I have a mix of local/offline/cloud backups, nothing was lost. Good for me, I noticed it 2 hours after software went insane and not when I actually needed one the backups. Brick missed the target.

Out of the cross-reference I get just one thing, I’m not alone (and that’s bad), it happened yesterday (2020.03.12) for me and for him (stanisluv), so this issue somewhat centralized. It’s strange that he has no evidence in MMS logs. It was easy for me to guess flip time, because I knew for sure that at time “A” everything was good and at time “B” when I noticed it, everything was bad, from time “A” to time “B” passed 7 hours. So I looked in logs only for this 7 special hours.

I’m 99.9% sure this issue has the same roots as last autumn borked settings (remote error passed to user computers), just several times more severe. Chances that this is a virus/ransomware almost near zero.

Only schedule *.tib files (and one of acronis cloud backups) were affected, everything else is all right, picky virus isn’t it? Also, let’s not forget MMS logs:

"Time": 00 17956 I0135003A: User '' (clientProfileID=''; clientSessionID='') is running command 'TODO: Fix command name for CommandID = "A"'.
"Time": 00 17956 I01900000: Deletion of online backup "A" has started.
“Time”: 00 17956 E01900002: Error 0x1900002: No Internet connection.
“Time”: 00 17956 E01900000: Failed to delete the online backup.
“Time”: 00 17956 I0135003B: Command 'TODO: Fix command name for CommandID = “A”' has completed successfully.

It survived

"Time": 00 17956 I0135003A: User '' (clientProfileID=''; clientSessionID='') is running command 'TODO: Fix command name for CommandID = "A"'.
"Time": 00 17956 I01900000: Deletion of online backup "B" has started.
“Time”: 00 17956 E01900002: Error 0x1900002: No Internet connection.
“Time”: 00 17956 E01900000: Failed to delete the online backup.
“Time”: 00 17956 I0135003B: Command 'TODO: Fix command name for CommandID = “A”' has completed successfully.

It survived

"Time": 00 17956 I0135003A: User '' (clientProfileID=''; clientSessionID='') is running command 'TODO: Fix command name for CommandID = "A"'.
"Time": 00 17956 I01900000: Deletion of online backup "C" has started.
“Time”: 00 17956 E01900002: Error 0x1900002: No Internet connection.
“Time”: 00 17956 E01900000: Failed to delete the online backup.
“Time”: 00 17956 I0135003B: Command 'TODO: Fix command name for CommandID = “A”' has completed successfully.

It vanished.

that’s not a virus, of course if Acronis didn’t go rogue.

Can you share one of the MMS logs (zipped ideally) to preserve the file name?  You can use OneDrive or similar via a private message to me if you prefer not to post the file to the forum.

Please do report this directly to Acronis and mark as urgent.

I have only a couple of systems plus some virtual machines that connect to the Acronis Dashboard via the MMMS service and these are not showing any issues / all files present etc.

Last time with the Dashboard server fiasco, we had hundreds of users reporting the issue within a matter of days, so not seeing that happening as yet!