Severity scale:  
  (98/100)

Remove Dotmap ransomware (Virus Removal Instructions) - Quick Decryption Solution

removal by Jake Doevan - - | Type: Ransomware

Dotmap ransomware is a file locking malware and a variant of Djvu virus family that demands ransom for the decryption tool

Dotmap ransomware

Dotmap is a ransomware-type virus that was first spotted by cybersecurity expert Michael Gillespie in mid-May 2019. The malware operates as an extortionist, meaning that it forcefully locks ups all personal files on the drive and demands ransom to be paid for the decryption tool.

Dotmap ransomware belongs to Djvu/STOP virus family, and also uses AES or similar robust encryption algorithms to perform the encryption which also appends .dotmap extension to picture, video, music, database, document, and other files. 

Victims are also present with a ransom note _readme.txt which explains what happened to their data and what steps they need to take in order to retrieve the access. Crooks prompt users to email them via bufalo@firemail.cc, gorentos@bitmessage.ch emails or contact via @datarestore Telegram account, and then pay a ransom of $980. Additionally, they also note that a 50% discount is offered within 72 hours of the infection.

Nevertheless, there is no need to contact crooks or pay the ransom, and rather focus on Dotmap ransomware removal. While no universal tool would decrypt all STOP variants, STOPDecrypter might be useful if the file-locking process was performed offline. 

Name Dotmap
Type Ransomware
Infiltration methods Spam emails, fake updates, repacked installers, software cracks, exploits, etc.
Malware family STOP/Djvu
File extension .dotmap
Ransom note _readme.txt
Contact bufalo@firemail.cc, gorentos@bitmessage.ch or @datarestore Telegram
Decryptable? No, although STOPDecrypter [download link] might be useful in some cases. Alternatively, you can try third-party recovery software – we provide all the links below
Termination Download and install reputable antivirus software
Recovery To repair infected system files, scan your computer with Reimage

There are several methods that hackers behind Dotmap ransomware use to propagate the virus. For example:

  • Spam emails;
  • Exploit kits;
  • Fake updates;
  • Web injects;
  • Unprotected RDP exploitation;
  • Drive-by downloads, etc.

Nevertheless, various STOP variants (Rumba and Tco) are known to be distributed with the help of adware bundles, as well as pirated software installers and its cracks. Additionally, other versions, such as Promorad, Promok, and Kroput, were also found to include a data stealer AZORult,[1] so be aware that Dotmap virus might consist of a secondary payload.

Once inside the system, Dotmap ransomware drops a ransom note into each of the affected folders, and it states the following:

ATTENTION!

Don't worry my friend, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-2jkyb95pOj
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
bufalo@firemail.cc

Reserve e-mail address to contact us:
gorentos@bitmessage.ch

Our Telegram account:
@datarestore

Your personal ID:

Do not trust the cybercriminals, even if they offer the discount and the free test decryption. Hackers might simply forget about you as soon as they get your money and never send you the decryption tool. Additionally, this would only prove that the ransomware scheme works and promote Dotmap ransomware development, infecting more victims worldwide.

Therefore, remove Dotmap ransomware with the help of powerful anti-malware software and then choose alternative methods for data restore. Additionally, experts[2] recommend scanning the device with Reimage for a quick recovery from the infection.

Dotmap ransomware virus
Dotmap ransomware is a cryptovirus that stems from one of the most prominent malware families - STOP

Do not download pirated software or its cracks – it is the quickest way to get infected with ransomware

Some of the infection methods that hackers use are sophisticated – they exploit software vulnerabilities and then redirect users to a malicious domain with the help of adware or ads on hacked sites. Once there, the malware can infiltrate the victims' machine without their interaction. In some cases, the virus might be hidden inside a picture or another seemingly harmless file with the help of Steganography[3] – a technique that allows malware to bypass security tools.

Nevertheless, most of the users get infected with ransomware in a very simple manner – they themselves initiate the infection process after opening the malicious attachments or clicking on links in a spam email, download pirated software or cracks, insufficiently protect their accounts, etc.

Therefore, besides employing tools like firewall, anti-malware software, ad-blocker, and similar, you also need to be internet smart and never endanger your computer. Avoid downloading suspicious installers, as well as software cracks/keygens, scan all the unknown executables with antivirus software, make sure to use two factor authentication where possible and ensure your account safety with strong passwords that are never reused and update your system along with all the installed programs as soon as security patches are released.

Delete Dotmap ransomware with comprehensive security software

To remove Dotmap ransomware, you will have to install anti-malware software if you have not done so already. Be aware that not all the AV engines might recognize the infection, and scans with multiple tools might be necessary to terminate the threat.

Nevertheless, probably the best way to take care of Dotmap ransomware removal is to access Safe Mode with Networking first because the safe environment is the best to troubleshoot problems, as well as delete viruses. We provide guidance on how to reach it below. Once inside, make sure you initiate a full system scan – it should terminate Dotmap virus along with any secondary payloads that might be hidden on your PC.

Once you are sure that the malware is gone, you can start the file recovery process. If you do not have backups prepared, there are several other options you can try – maybe it will help you recover at least some of your data, although the chances are relatively slim.

Offer
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to remove virus damage. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with SpyHunter 5.
Alternative Software
Different security software includes different virus database. If you didn’t succeed in finding malware with Reimage, try running alternative scan with Combo Cleaner.

To remove Dotmap virus, follow these steps:

Remove Dotmap using Safe Mode with Networking

Before you remove Dotmap ransomware, enter Safe Mode with Networking as follows:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove Dotmap

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete Dotmap removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove Dotmap using System Restore

System Restore can also be useful when trying to terminate the virus:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Dotmap. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that Dotmap removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Dotmap from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If your files are encrypted by Dotmap, you can use several methods to restore them:

Data Recovery Pro might retrieve at least some of your files

While this tool is not originally designed to restore ransomware encrypted files, victims claimed that it did help them in some cases:

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by Dotmap ransomware;
  • Restore them.

Windows Previous Versions Feature might be useful when trying to recover .dotmap encrypted files

If you had System Restore enabled before the virus struck, you should try Windows Previous Versions Feature.

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

In some cases, ShadowExplorer would be able to restore all files

If the crypto malware failed to delete Shadow Volume Copies, your chances of recovering files are quite high if you tools like ShadowExplorer.

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Make use of STOPDecrypter

You can also try using  STOPDecrypter [download link] that would be able to decipher files if the encryption process was performed offline.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Dotmap and other ransomwares, use a reputable anti-spyware, such as Reimage, SpyHunter 5Combo Cleaner or Malwarebytes

About the author

Jake Doevan
Jake Doevan - Computer technology expert

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Jake Doevan
About the company Esolutions

References


Your opinion regarding Dotmap ransomware