It happened on April 17,2017 starting at about 04:00AM local time.
There is two(2) MOST unfortunate parts of this attack. First the backup drive was connected to do a normal nightly backup. Second, I discovered the infection at about 06:19AM, when a message appeared on the screen. The message informed me of some files waiting to be written to my CD Drive???. Immediately, I searched Task Manager and found a file "aaaaaaaannnbest.exe" running.
Immediately killed the process(99.95% damage was already done?). Started searching for the offender, and located multiple instances on disk as well as registry. Virus destroyed, but all files except for Win7 OS destroyed with the addition
of the .id-DCCC8A87.[firstname.lastname@example.org].wallet extension to every file.
I am in dire straits to recover files. There was NEVER a ransom note displayed, or that I have been able to locate anywhere.
A am hopeful someone will have some way of developing a decryptor for this menace.