My understanding of ransomware is that it will usually sit dormant in most cases, until an administrator logs in to a computer and it has the credentials to exploit.
Using the backup and antivirus method you should be able to find where it sits should you come to recover your systems. Your backup system is not protection against ransomware.
As far the synology box being infected, are these not usually viruses programmed for Windows machines?