- This topic has 4 replies, 1 voice, and was last updated 5 years, 2 months ago by .
- Topic
Hello. Hope someone here can help me. Our main server was infected with .Wallet ransomware. This does not only affect our local network, but also remote computers from various locations. This started after one of our staff opened an email containing the .Wallet virus. It spreads rapidly to our local networks and then, also infects files from our remote offices. After gathering data from affected locations, here are the names we have found. I know that these are part of Dharma Ransomware.
amagnus@india.com.wallet
amanda_sofost@india.com.wallet
bitcoin143@india.com.wallet
diablo_diablo2@aol.com.wallet
enterprise_lost@aol.com.wallet
fly_goods@aol.com.wallet
grand_car@aol.com.wallet
gutentag@india.com.wallet
injury@india.com.wallet
interlock@india.com.wallet
Lavandos@dr.com.wallet
legionfromheaven@india.com.wallet
magnetvec@india.com.wallet
makedonskiy@india.com .wallet
mission_inposible@aol.com.wallet
mkscorpion@india.com.wallet
p_pant@aol.com.wallet
stopper@india.com.wallet
supermagnet@india.com.wallet
support_files@india.com.wallet
SupportForYou@india.com.wallet
xmen_xmen@aol.com.walletHow can we recover files with the mentioned email – extension combination? I am certain that we already removed the ransomware virus from all the servers. Our main concern right now is to retrieve all .wallet files without paying the ransom.
Any help will be much appreciated.