Problems using malware remover

Discussion on setting up QNAP NAS products.
Post Reply
DrJ76
Know my way around
Posts: 209
Joined: Thu Jun 26, 2014 6:51 pm

Problems using malware remover

Post by DrJ76 »

Hello. I have just received a mail from qnap that told me to install and run malware remover.

I have installed the app from app center, but when I click in "Open", nothing happens, what is it supossed to do?


Best regards and thank you in advance.
User avatar
OneCD
Guru
Posts: 12163
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Problems using malware remover

Post by OneCD »

Check your system logs. Actions performed by MalwareRemover are shown there. ;)

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
DrJ76
Know my way around
Posts: 209
Joined: Thu Jun 26, 2014 6:51 pm

Re: Problems using malware remover

Post by DrJ76 »

OK, I have look at them and I see some malware removed messages, grrr, Should I be scared?

I have download the system, but the recommendation of changing the passwords is very annoying for me, I have it used in a lot of devices, grrrr..

Do you think it is completly necessary?

Here are the messages:


Type Date Time Users Source IP Computer name Content
Information 2017/05/19 19:09:05 System 127.0.0.1 localhost [MalwareRemover] Scan completed and malware deleted.
Information 2017/05/19 19:09:03 System 127.0.0.1 localhost [MalwareRemover] Malwares process killed: qcloud_ag (7106)
Information 2017/05/19 19:08:52 System 127.0.0.1 localhost [MalwareRemover] Malware removed: /home/httpd/cgi-bin/syncTime.cgi
Information 2017/05/19 19:08:50 System 127.0.0.1 localhost [MalwareRemover] Malware removed: /home/httpd/cgi-bin/authLogin.cgi
Information 2017/05/19 19:08:47 System 127.0.0.1 localhost [MalwareRemover] Malware removed: /share/MD0_DATA/.log/.cgi_log
Information 2017/05/19 19:08:44 System 127.0.0.1 localhost [MalwareRemover] Malware removed: /share/MD0_DATA/.qpkg/.myQNAPcloud
Information 2017/05/19 19:08:38 System 127.0.0.1 localhost [MalwareRemover] Malware removed: /tmp/config/arm.tar.gz
Information 2017/05/19 19:08:35 System 127.0.0.1 localhost [MalwareRemover] Malware removed: /tmp/config/autorun.sh






Best regards and thank you in advance
User avatar
OneCD
Guru
Posts: 12163
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Problems using malware remover

Post by OneCD »

Yes, you had malware so you should definitely change your admin password at least.

This is because it's possible your existing password was sent out to the originators of the malware. And even though you have removed the malware, they can login again as admin and reinstall it. ;)

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
DrJ76
Know my way around
Posts: 209
Joined: Thu Jun 26, 2014 6:51 pm

Re: Problems using malware remover

Post by DrJ76 »

Ok, I will do so, thank you very much

Enviado desde mi GT-I9505 mediante Tapatalk
DrJ76
Know my way around
Posts: 209
Joined: Thu Jun 26, 2014 6:51 pm

Re: Problems using malware remover

Post by DrJ76 »

How can the malware been installed?
User avatar
OneCD
Guru
Posts: 12163
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Problems using malware remover

Post by OneCD »

Originally - through vulnerabilities in the NAS OS. But once the admin password is known, it could be done at the command line. Even with a patched NAS.

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
DrJ76
Know my way around
Posts: 209
Joined: Thu Jun 26, 2014 6:51 pm

Re: Problems using malware remover

Post by DrJ76 »

OneCD wrote:Originally - through vulnerabilities in the NAS OS. But once the admin password is known, it could be done at the command line. Even with a patched NAS.

I see, grrrrr... I hope it does not happen again....
marumi
First post
Posts: 1
Joined: Tue May 30, 2017 8:54 pm

Re: Problems using malware remover

Post by marumi »

20170527001.jpg
I'm same, too.
You do not have the required permissions to view the files attached to this post.
User avatar
Moogle Stiltzkin
Guru
Posts: 11445
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: Problems using malware remover

Post by Moogle Stiltzkin »

i personally tested and it did not report any malware for me. either i'm effective at warding out malware, or malware remover is not detecting any dodgy things that got onto my device :X for now i just have to trust i'm in the clear.

in regard to password use the max length allowed for qnap also make it complicated. i use a password generator which does that for me. if i ever get compromised i can easily generate another the same way. don't recycle passwords because if it ever gets leaked, the hackers will try using that password on your other accounts.... that is bad practice, don't do that :S

[youtube=]t8SQo3R7qeU[/youtube]


also if you use password manager o recommend keepass since you store the key and database on your own storage. i don't trust stuff like last pass because it stores it on the cloud, and when they changed their monetization policy their holding your database hostage unless you subscribe to the new model after they got bought out etc... so yes keepass avoids that nonsense and other cloud security liabilities :?
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
Post Reply

Return to “Turbo Station Installation & Setup”