What should I do if I found the NAS encrypted by Deadbolt?


최신 업데이트일: 2022-10-06

Applicable Products

  • Security
  • Malware Remover

Detail

You may have received the following message:

Detected high-risk malware. To protect your device, please immediately update the firmware to the latest version, restart the device, and then perform a malware scan to remove the malware.

After investigation, we believe that the attack is related to qsa-22-24.

We strongly recommend performing the following steps:

  1. Take a screenshot of deadbolt ransomware page and save the file to your computer.

  2. Access QTS web interface by adding /cgi-bin/index.cgi after the URL https://NAS_IP or http://NAS_IP:8080.
    (for example the NAS has IP address has 192.168.0.2 , using https://192.168.0.2/cgi-bin/index.cgi or http://192.168.0.2:8080/cgi-bin/index.cgi)

  3. Log in to QTS as an administrator

    1. Go to myQNAPcloud app > Auto Router Configuration, disable Auto Router Configuration.
    2. Open App Center, upgrade all the apps to latest version and install Malware Remover if not installed.
    3. Open Malware Remover, click "Start Scan" and wait for Scan Complete
    4. Upgrade the NAS firmware to the latest version use QTS web interface via Control Panel > Firmware Upgrade.
  1. To maximize security, disable port forwarding to stop exposing the NAS to the internet and follow the best practice of enhancing NAS security.

Further Reading



이 기사가 도움이 되었습니까?

21% 의 사용자들이 도움이 된다고 생각할 것입니다.
피드백을 주셔서 감사드립니다.

이 기사가 어떻게 개선될 수 있을지 말해 주십시오.

추가 피드백을 제공하려면 아래에 포함하십시오.

사양 선택

      더 보기 적게 보기

      다른 국가/지역 사이트:

      open menu
      back to top