ech0raix

124»

All Replies

  • Macace
    Macace Posts: 9  Freshman Member
    First Comment Friend Collector

    Hello

    I have removed the automatic generated Cloud User as follow:

    Go to the MyZyxel Cloud Website and do a disconnect from your NAS from the MyZyxel Service.

    After this uninstall the MyZyxel App in the NAS. After this the Cloud User should automatic remove after a short time.

    I have one of the 10 NAS that had not delete the Cloud User after this , but it is not the infected one. I dont know why.

    After the new Informations I think the Cloud User is not the main problem. With the new FW it should be save at the moment. But how long ?

  • LDS
    LDS Posts: 2
    First Answer First Comment
    edited July 25

    Today 25.07.2024 C3RB3R crypted my ech0raix crypted file.

    So. Zyxel DO SOMETHING!!!

    Find a solution for US.

    Or, you gave acces to this pirates?

  • Macace
    Macace Posts: 9  Freshman Member
    First Comment Friend Collector

    @LDS

    How is this possible?

    Did you install the newest Firmware after the first Infektion and disable the complete internet access for the NAS after the update ?

    From the 13 NAS that I have in service there was only one infected. After that I have done the update and close Internet complete for the other 12. There are actual no more problems.

    There is no way to decrypt the files. To pay the hackers is a 50:50 chance.

    In your case, when i understand correct, your files are now double crypted. In my opinion delete all and use your backup.

  • gabimes
    gabimes Posts: 3  Freshman Member
    First Comment Friend Collector

    @Macace

    On NAS542 I was encrypted with eCh0raix Ransomware
    I have a backup on an external hard drive made recently, but when restoring at the end of the process, we have the WRONG PASSWORD error written in red

    Is something that we didn't do right.

Consumer Product Help Center