A1Tft Ransomware (. A1Tft Files) — How to Remove Virus?
What Is A1Tft Virus? the Pattern of Renaming Is This: [Random String]. A1Tft. in the Process of Encryption, a File Entitled, for Instance, “Report. Docx” Will...
What is A1tft virus?
The pattern of renaming is this: [random string].a1tft. In the process of encryption, a file entitled, for instance, “report.docx” will be renamed to “report.docx.237cboyqOCVY17808cgf671fw3bbcG.a1tft”.
In every folder containing the encrypted files, a ihr6_HOW_TO_DECRYPT.txt file will appear. It is a ransom money memo. It contains information on the ways of contacting the racketeers and some other remarks. The ransom note most probably contains instructions on how to purchase the decryption tool from the tamperers. That is how they do it.
| Name | A1tft Virus |
| Ransomware family1 | Hive ransomware |
| Extension | .[random string].a1tft |
| Ransomware note | ihr6_HOW_TO_DECRYPT.txt |
| Detection2 | UDS:Backdoor.Win32.Farfli.bskz, Cerbu.129735, Trojan:MSIL/AgentTesla.DCP!MTB |
| Symptoms | Your files (photos, videos, documents) have a .[random string].a1tft extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by A1tft virus |
In the picture below, you can see what a folder with files encrypted by the A1tft looks like. Each filename has the “.[random string].a1tft” extension added to it.
How did A1tft ransomware end up on my PC?
There are currently three most exploited ways for evil-doers to have ransomware working in your system. These are email spam, Trojan infiltration and peer networks.
If you open your mailbox and see letters that look just like notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose addresser is unknown to you, be wary of opening those letters. They are very likely to have a viral item attached to them. Thus it is even more dangerous to download any attachments that come with letters like these.
Another option for ransom hunters is a Trojan horse scheme3. A Trojan is an object that infiltrates into your computer pretending to be something legal. For instance, you download an installer of some program you want or an update for some program. However, what is unboxed turns out to be a harmful program that encodes your data. As the installation wizard can have any title and any icon, you’d better be sure that you can trust the source of the stuff you’re downloading. The optimal way is to trust the software developers’ official websites.
As for the peer-to-peer file transfer protocols like torrents or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. So you’d better be using trustworthy websites. Also, it is a good idea to scan the folder containing the downloaded objects with the antivirus as soon as the downloading is done.