

look for your architecture (uname -a) for i386 or x86_64: Linux NAS-XXXX 4.14.24-qnap #1 SMP Tue Mar 2 06:10: x86_64 GNU/Linux.Sudo mount -t cifs -o user= /// /mnt/rescue-share Connect to your samba share: mkdir /mnt/rescue-share.(Confirm it with ‘Y’) You should get a shell. After Login you get a screen with some option.You should use your admin credentials to login.

Login over SSH (Putty on Windows) on your NAS.
DOWNLOAD 7ZX PASSWORD
You should use your Windows account with a password (if your account haven’t one, create it. Create a samba share on your windows computer.You need to have access to the ssh terminal of your QNAP NAS (you can activate it over the GUI it doesn’t change your data). The files are deleted after archiving and encrypting with 7z and exists in the not-allocated space of your disk.
DOWNLOAD 7ZX ARCHIVE
If circumstances force you to download something from peering networks – scan every downloaded folder or archive with antivirus software. No one can control which files are packed in the seeding, so you can discover a huge pack of different malware after downloading. I am talking about peering networks, such as torrents or eMule. There is also the third way of ransomware injection, however, it becomes less and less popular day-to-day. Sometimes, trojan viruses can be masked as legit programs, and ransomware will be offered for download as an important update, or a big pack of extensions that are essential for proper program functioning.
DOWNLOAD 7ZX INSTALL
In case of trojans presence, you will be offered to download and install ransomware on your PC under the guise of something legit, like a Chrome update, or update for the software you are storing on your computer. If you open this file – your system will get infected by Qnap NAS. All such letters contain the attached file, which is used as a ransomware carrier. But all such messages are sent from unknown email addresses, not from familiar official emails of these companies. You may see a lot of messages on your email, stating that you need to pay different bills or to get your parcel from the local FedEx department. However, nowadays there are only two ways of Qnap NAS injection – email spam and trojans. KU1o8mGG4p8moefySdZSI85HX6C2HrkK+bxGuHnuXSbStdiDiGsOyl2BsIZA1x2/d+yiEVnRnJ3TVu1g2C1v8MLKuykVkIhCnCBM/im9MvPs74klClQaL8DxUDLznCwiC0k/0KK3r+usGQXDYarxF34da5kXweU+vv7rS4q9fRUzKW30UDBE9OqpYs3bPENspssr8C2hcEqJxNPtPY2nswVC95tgVlDXdET3w+TIqEIzzQEVxUc7TN55GW8ajyu2d1EO3QVxkTKreoMVED5qDuMXryZe24NfOGuJoNN644JkTChwemiahcdMI77NPa47SDmK8uFiAIHSEXGOR/soqg= Gvka2m4qt5fod2fltkjmdk4gxh5oxemhpgmnmtjptms6fkgfzdd62tad.onion Visit the following pages with the Tor Browser: If you need help, please Google for “access onion page”.Ģ. To purchase your key and decrypt your files, please follow these steps:ġ. This key is stored in our server and the only way to receive your key and decrypt your files is by making a Bitcoin payment. The !!!READ_ME.txt file by the Qnap NAS ransomware states the following frustrating information: !!! All your files have been encrypted !!!Īll your files were encrypted using a private and unique key generated for the computer.
