Raid not active after DEADBOLT Ransomware

Questions about SNMP, Power, System, Logs, disk, & RAID.
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

Hi all.

Yes I am one of the people who even this late still got deadbolted this past weekend. Due to the fact I have no backups and cannot afford to lose this data I paid the ransom and got the key. I put the key in and it removed the deadbolt prompt upon login. I was assuming this would fix more than it did. Now when I log into the NAS it tells me that the raid status is "Not Active" but that all the disks are "Good". The onboard recover raid group feature leads me to a message that says:
"Failed to recover storage pool. Possible reasons:
Someone inserted new disks, or the data is damaged.
To continue, insert the original disks into the NAS and
recover the pool again, or delete the pool and create a new one. "

I was able to ssh into the device (TS - 451) and run md_checker and got the status as OFFLINE. I can see all the drives and each of those is listed as active.

I have followed a few other posts and so far none of the commands have worked to restore the raid. I am really at a loss. I put a ticket in with QNAP but it has been days now and they have not replied.

Does anyone have any thoughts? I am not technically savvy and really need this restored. I am also aware once the raid volume is repaired that I will need Emsisoft and my Key to decrypt it, which is fine. I just cannot get this device to recognize this raid.
You do not have the required permissions to view the files attached to this post.
User avatar
dolbyman
Guru
Posts: 35273
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Raid not active after DEADBOLT Ransomware

Post by dolbyman »

Open a ticket with QNAP and have them take a look at it
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

I did, I havent heard back.
User avatar
dolbyman
Guru
Posts: 35273
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Raid not active after DEADBOLT Ransomware

Post by dolbyman »

You could try to reinit the LVM, but without backups I would not go to that step yet (and wait for QNAP)
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

I dont know what LVM is and unless someone can give me detailed steps of how to troubleshoot, i have no choice but to wait for qnap.
User avatar
dolbyman
Guru
Posts: 35273
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Raid not active after DEADBOLT Ransomware

Post by dolbyman »

command is issued via SSH (make sure to use the 'admin' account)

Code: Select all

/etc/init.d/init_lvm.sh
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

says "no such file or directory"
User avatar
dolbyman
Guru
Posts: 35273
Joined: Sat Feb 12, 2011 2:11 am
Location: Vancouver BC , Canada

Re: Raid not active after DEADBOLT Ransomware

Post by dolbyman »

What user was used to login to SSH ?
User avatar
OneCD
Guru
Posts: 12146
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Raid not active after DEADBOLT Ransomware

Post by OneCD »

... and please post a screenshot of your command and the shell response.

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

admin, the only user account there is
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

Here is the screen cap
QNAP2.jpg
You do not have the required permissions to view the files attached to this post.
User avatar
OneCD
Guru
Posts: 12146
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Raid not active after DEADBOLT Ransomware

Post by OneCD »

dillonalexander wrote: Tue May 17, 2022 3:25 am Here is the screen capQNAP2.jpg
You've misspelt the script name. ;)

Please try it again.

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

Ok, sorry. Im a moron on this **. Here is what it says now:
QNAP3.jpg
You do not have the required permissions to view the files attached to this post.
User avatar
OneCD
Guru
Posts: 12146
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Raid not active after DEADBOLT Ransomware

Post by OneCD »

What does 'md_checker' show now?

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
dillonalexander
New here
Posts: 8
Joined: Tue May 17, 2022 2:22 am

Re: Raid not active after DEADBOLT Ransomware

Post by dillonalexander »

QNAP4.jpg
that worked!!!!! now i can see the drives again and recovered them. Now i just have to decrypt the data.
You do not have the required permissions to view the files attached to this post.
Post Reply

Return to “System & Disk Volume Management”