Ransom

How to remove “Ransom:Win32/Bartcrypt.A”?

Malware Removal

The Ransom:Win32/Bartcrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Bartcrypt.A virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Bartcrypt.A?


File Info:

crc32: AA04BECA
md5: d9fe38122bb08d96ef0de61076aa4945
name: D9FE38122BB08D96EF0DE61076AA4945.mlw
sha1: 6f27e8e1253829ac6c2819a16d01fc5acd3796ee
sha256: c285e376201e2941154ec1a9acd8658cd5e0ea975c694a3fe3e9a9897efc2680
sha512: 8597dc034abe3ca89050c5c5d12bd3aec1a195a3d4656aa453f87f328f4e3c4bbbafcb26556a9d9d3adf3f47fea0af6e4cafe99fdc7bd03e33facf4b5f0c2f32
ssdeep: 3072:+G9fV7I6P02uiH3v3T0XBNAQc5d4AU8buatjmXd:+GrP0piXv3Qc5dDJtjmt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Bartcrypt.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4943
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Bart
CylanceUnsafe
ZillyaTrojan.Bart.Win32.2
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Bartcrypt.7564241f
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.22bb08
SymantecRansom.BART
ESET-NOD32a variant of Win32/Filecoder.Bart.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Bart.a
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusTrojan.Win32.Encoder.eeftgm
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
ComodoMalware@#27u12xitz22jl
BitDefenderThetaAI:Packer.8B2E5D061F
VIPRETrojan.FakeAlert
TrendMicroRansom_BARTZ.B
McAfee-GW-EditionBehavesLike.Win32.RansomGandcrab.ch
FireEyeGeneric.mg.d9fe38122bb08d96
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bart.a
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.199A0CD
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Bartcrypt.A
ArcabitTrojan.Ransom.REntS.Gen.1
AegisLabTrojan.Win32.Bart.j!c
GDataGen:Heur.Ransom.REntS.Gen.1
AhnLab-V3Trojan/Win32.Bart.C1490583
McAfeeGenericRXCX-XM!D9FE38122BB0
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Bart
MalwarebytesRansom.Bart
PandaTrj/CI.A
TrendMicro-HouseCallRansom_BARTZ.B
RisingTrojan.Generic@ML.80 (RDML:zMzVuZKif+TyWaKSLvKRlw)
YandexTrojan.Bart!rQjp6ake2bk
IkarusTrojan-Ransom.Bart
FortinetW32/SimpleEncoder.A!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom:Win32/Bartcrypt.A?

Ransom:Win32/Bartcrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment