This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Asustor Nas DeadBolt Infection

1 min read

This thread's last reply is from June 18, 2022, 9:39 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

My Asustor 5002t has been infected with Deadbolt Ransome Ware.
https://www.trendmicro.com/en_us/research/22/f/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html
I used this link to try to learn how to 32 bit key in an infected file. Then I used Emsisoft tool decrypt_DeadBolt.exe added the 32 bit key but it said wrong key.

I used HEXMEX to find the deadbolt text in two infected files(One was a video file and the other was a Thumbs image file. Then I followed Instructions in the above link in order to create my deadbolt analysis.pdf attached.

When I used 1FCD98C3168CE663D3C72799B3040EE1 or 5F3A1384679CF07808C12FC087E37D44 from this analysis in "Emsisoft tool decrypt_DeadBolt.exe" It always says wrong key....So no joy in understanding and understanding the fix for Deadbolt Ransomeware.

Asustor'solution was to restore a backup of the NAS. Albeit I did not have a ASUSTOR backup on the NAS.
The best place to get help with Ransomware is ... https://www.bleepingcomputer.com/forums/t/608844/how-to-post-a-topic-asking-for-help-with-ransomware/ ... who have a few helpers who specialise in dealing with it.

Sadly, even with specialist help, there is no guarantee that you wil be able to recover any files that have already been encrypted.