A1Tft Ransomware (. A1Tft Files) — How to Remove Virus?

What is A1tft virus?

The pattern of renaming is this: [random string].a1tft. In the process of encryption, a file entitled, for instance, “report.docx” will be renamed to “report.docx.237cboyqOCVY17808cgf671fw3bbcG.a1tft”.

In every folder containing the encrypted files, a ihr6_HOW_TO_DECRYPT.txt file will appear. It is a ransom money memo. It contains information on the ways of contacting the racketeers and some other remarks. The ransom note most probably contains instructions on how to purchase the decryption tool from the tamperers. That is how they do it.

NameA1tft Virus
Ransomware family1Hive ransomware
Extension.[random string].a1tft
Ransomware noteihr6_HOW_TO_DECRYPT.txt
Detection2UDS:Backdoor.Win32.Farfli.bskz, Cerbu.129735, Trojan:MSIL/AgentTesla.DCP!MTB
SymptomsYour files (photos, videos, documents) have a .[random string].a1tft extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by A1tft virus

In the picture below, you can see what a folder with files encrypted by the A1tft looks like. Each filename has the “.[random string].a1tft” extension added to it.

That is how encrypted “.[random string].a1tft” files look.

How did A1tft ransomware end up on my PC?

There are currently three most exploited ways for evil-doers to have ransomware working in your system. These are email spam, Trojan infiltration and peer networks.

If you open your mailbox and see letters that look just like notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose addresser is unknown to you, be wary of opening those letters. They are very likely to have a viral item attached to them. Thus it is even more dangerous to download any attachments that come with letters like these.

Another option for ransom hunters is a Trojan horse scheme3. A Trojan is an object that infiltrates into your computer pretending to be something legal. For instance, you download an installer of some program you want or an update for some program. However, what is unboxed turns out to be a harmful program that encodes your data. As the installation wizard can have any title and any icon, you’d better be sure that you can trust the source of the stuff you’re downloading. The optimal way is to trust the software developers’ official websites.

As for the peer-to-peer file transfer protocols like torrents or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. So you’d better be using trustworthy websites. Also, it is a good idea to scan the folder containing the downloaded objects with the antivirus as soon as the downloading is done.

Elena Rostova

Elena Rostova

Lead Health, Wellness & Medical Journalist

Elena Rostova holds a Master's degree in Public Health Journalism. She covers groundbreaking medical research, holistic wellness trends, mental health awareness, and nutritional science.

Share this article
Twitter Facebook Pinterest