[SOLVED] Ransomware-Are my disks still good?

May 28, 2020
2
0
10
Hi,

My first post here.

I'm hoping this isn't a silly question, but I don't seem to be able to find a definitive answer.

My NAS drive was hit with ransomware (MegaLocker) about a year ago. At the time I just removed all of the drives, replaced them with larger drives, setup the system again and restored from offline backups. I also learned my lesson, beefed up security and removed the NAS from outside access via direct connection to my PC.

My question is; I'm paranoid about reusing the disks that were encrypted. I am worried for no reason? I have connected the drives to an old laptop and wiped them with AOMEI Disk Partition.

Are they safe to re-use in my NAS?
 
Solution
There is a very slight chance that the drives are infected with an MBR rootkit. This could only happen if your NAS OS itself was compromised. This might get into 'tinfoil hat' territory. ;)

If you want to go the extra mile, boot off a Windows recovery/OS USB drive with ONLY one of the drives attached (no OS drives, no data drivers - nothing else). Go into the recovery CLI and run fix MBR on the drive. Rinse and repeat for each affected drive.
There is a very slight chance that the drives are infected with an MBR rootkit. This could only happen if your NAS OS itself was compromised. This might get into 'tinfoil hat' territory. ;)

If you want to go the extra mile, boot off a Windows recovery/OS USB drive with ONLY one of the drives attached (no OS drives, no data drivers - nothing else). Go into the recovery CLI and run fix MBR on the drive. Rinse and repeat for each affected drive.
 
Solution