Infected with a ransomware; trying to recover my files using a HDD to USB docking station on my server

z3nth10n

New Member
Mar 26, 2019
15
0
1
26
Hi,

the other day I was infected with ransomware. I'm not at home, so a friend connected the hard drives to the server using a docking station: https://www.tooq.com/product.php?id=1523

Right now, I'm trying to recover my files by using this docking station with my two 2TB hard driver connected.

I used this docking station before to copy the files from a hard-drive to the other in Windows without problems.

But for some reason the docking station is not being detected (at least, the hard drives).

This are the commands that I executed to check if the hard drivers are detected:

LcEixi4.jpg

As you can see on the image from above the usb is detected.

MnxNIXX.jpg


Also there.

But in this images you can see that the unique disk that there are detected are the ones from my server (2x500GB):

0HRmQcG.jpg


97T0s1a.jpg


Lmuz9wl.jpg


G63JPx6.jpg


I though it can be caused because of leaking drivers/controllers but I couldn't see anything. On the webpage you can see that there are aavailable drivers for Linux, but if you download the zip you can't see them.

I call this evening to the support of the store and they told me they don't have any idea about this. Also the HDD should be detected at the same time you connect them.

I tried to install ntfs-3g and this didn't worked. Also I tried a reboot and it didn't worked.

So I can't do any USB passthough yet...

PD: Output of desmg after first reboot: https://pastebin.com/3ckXM385

Any help is welcome! Thanks!
 
Last edited:
I'm not sure do you try to passtrough the USB to a VM or do you want to recover on Proxmox?

From what i see your "root@proxmox" lsusb is empty no device, which is the default when you passed it to a vm.

Are you sure the docking station is connected right?
 
Well, I added it to the hardware of my VM, maybe by removing and rebooting could solve the problem?
 
The VM is Debian and this is what I get:

af49d4f844f5dbdf950eea44a0422943.png


I think I got this at the first time.

Is there any relevant information at the "demsg" command I attached on pastebin?
 
Last edited:
6ec3186ff5b17c759eedcc4c1fe95baf.png


Only sda is detected. It should have sdb and sdc from the HDD docking station? I didn't not mounted them...
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!