i've read about tons of ransomwares of this type, however, this seems to be an unknown type of extension.
I've seen the coinvault decryptor tool has some known extensions but this one wasn't included.
The virus infected the server of one of our customers but we don't see from which PC the virus started, but we do know from whom it came. Still, this person's PC doesn't seem to be infected either, nor is his profile on the terminal server. We installed bitdefender and it found this worm, which was found on all 3 servers (one physical DATA / Hyper-V host, one Hyper-V terminal server and one Hyper-V webserver).
Is there a way to decrypt my files? Perhaps if i changed the extension of the files the encryption might be of the same type other known extensions use? Just thinking out loud here
The ransomware infected files and virus found by Bitdefender are below.
Thanks in advance,