Ransomware Attack (.neras) am I still infected?

Dear Community,

Our server have been partially hit with a ransomware virus today (a handful of files appear with an encrypted .neras file extension).

Our goal is to stop the spread of the virus to prevent more files from being encrypted.

We have run MBAM and FRST64 on our main server, Please find attached log files for your review.

We are kindly asking you for a solution so that we can reconnect the hard drives and resume our operations.

Thank you in advance.

I don’t see anything malicious in logs so I pressume that TrendMicro removed him. However, before reattaching production disks I recommend testing with disk filled with “fake” documents.