Remove .MASTER Ransomware and Restore Files (Update July 2017)

Remove .MASTER Ransomware and Restore Files (Update July 2017)


with SpyHunter

Scan Your System for Malicious Files
Note! Your computer might be affected by .master Ransomware and other threats.
Threats such as .master Ransomware may be persistent on your system. They tend to re-appear if not fully deleted. A malware removal tool like SpyHunter will help you to remove malicious programs, saving you the time and the struggle of tracking down numerous malicious files.
SpyHunter’s scanner is free but the paid version is needed to remove the malware threats. Read SpyHunter’s EULA and Privacy Policy

An article created to show you how to remove the .MASTER file virus (BTCWare’s latest variant) and restore files that have been AES encrypted by this virus.

A ransomware infection, known to be the notorious BTCWare ransomware has been released as a new variant of the virus family. Unlike the other BTCWare versions, the .master iteration cannot be decrypted so far and uses an AES encryption algorithm to extort victims whose computers have been infected. The victims have to pay a hefty ransom fee in order to get their files decrypted by the ones behind the .master ransomware infection. In case your computer has been infected by this virus, we advise you to read this article thoroughly.

Threat Summary

Name.master Ransomware
TypeRansomware, Cryptovirus
Short DescriptionEncrypts the files on the infected computer using AES algorithm. Demands ransom payoff in BitCoin. The ransom varies.
SymptomsThe files are encrypted with the .master file extension added to them. The virus drops a ransom note, named !#_RESTORE_FILES_#!.inf.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by .master Ransomware


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .master Ransomware.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Update July 2017 A new version of BTCWare ransomware has come out into the wild. The virus uses a new malicious file extension, called .aleta which i adds to the encrypted files. Malware eresearchers believe it is spread via malicious spam e-mails carrying documents that contain malicious macros within them. Furthermore, researcher Michael Gillespie notified of a decrypter being released for the .MASTER BTCWare variant. You can now decrypt your files for free if you have saved them.

.master Ransomware Distribution Methods

Since the Master ransomware as many refer to it with this name is a variant of the BTCWareransomware, it may use the same methods to be spread and infect victims. The primary strategy of those methods is to send a massive spam campaign with e-mails that aim for one thing only – to convince unsuspecting users that the situation is critical and they must either click on an e-mail attachment or open a web link that may eventually lead to infection. To do this, Master ransomware may pretend to be a large organization, such as:

  • Amazon
  • PayPal
  • FedEx
  • DHL
  • eBay
  • Other

The messages usually have deceptive content, also known as “social engineering”. They may claim that there is an order awaiting confirmation or any other form invoices or important documents. Then, the user may be misled to click on the malicious e-mail.

BTCWare .master Ransomware – Analysis

After the infection file of the .master ransomware variant is opened, the virus begins to drop it’s payload. This happens by either extracting the payload onto the infected computer or simply connecting to a remote server hosted by the cyber-criminals and download it from there. After this has been done, the malicious files of Master ransomware are then dropped onto the computer of the user and may reside in the following locations:

  • %AppData%
  • %Roaming%
  • %Local%
  • %LocalLow%
  • %Temp%

Those files include the ransom note of .master ransomware which is named !#RESTORE_FILES_#!.inf. It has the following content:

The .master ransomware virus may begin to modify multiple different Windows processes on the compromised computer system. This is done with the purpose of changing crucial settings on the infected computer, like deleting the backups and shadow volume copies by using the following Windows Command Prompt commands:

→ process call create “cmd.exe /c
vssadmin.exe delete shadows /all /quiet
bcdedit.exe /set {default} recoveryenabled no
bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures

.master Ransomware’s Encryption Process

For the encryption process of the BTCWare .master ransomware variant to succeed, the virus uses a patched AES encryption algorithm. If applied properly, it is very difficult to decrypt the encrypted files by this virus. The files that the .master ransomware looks for to encrypt on infected computers are usually the following:

→ .1c, .3fr, .accdb, .ai, .arw, .bac, .bay, .bmp, .cdr, .cer, .cfg, .config, .cr2, .crt, .crw, .css, .csv, .db, .dbf, .dcr, .der, .dng, .doc, .docm, .docx, .dwg, .dxf, .dxg, .eps, .erf, .gif, .htm, .html, .indd, .iso, .jpe, .jpeg, .jpg, .kdc, .lnk, .mdb, .mdf, .mef, .mk, .mp3, .mp4, .mrw, .nef, .nrw, .odb, .ode, .odm, .odp, .ods, .odt, .orf, .p12, .p7b, .p7c, .pdd, .pdf, .pef, .pem, .pfx, .php, .png, .ppt, .pptm, .pptx, .psd, .pst, .ptx, .r3d, .rar, .raw, .rtf, .rw2, .rwl, .sql, .sr2, .srf, .srw, .tif, .wb2, .wma, .wpd, .wps, .x3f, .xlk, .xls, .xlsb, .xlsm, .xlsx, .zip

After the .master ransomware has already encrypted the files, the virus then displays the files with the .master file extension after their name, for example:

It is believed that the cyber-criminals behind the .master virus have chosen this file extension in particular, because all of the previous variants of BTCWare have already been decrypted using a master decryption key which malware researchers uncovered earlier. And by doing this, the cyber-criminals might aim to mock those researchers.

Remove BTCWare and Restore .master Encrypted Files

Before removing BTCWare .master variant, it is important to backup the encrypted files beforehand.

Then, you can proceed with the removal of the virus. For it to succeed, we advise following the removal instructions underneath. They are specifically designed to help you in isolating the threat and removing all related objects to .master ransomware. In case you lack the experience to remove this virus manually, cybersec experts often advise to use and advanced anti-malware program which will automatically take care of the removal process for you.

In case you are looking for a method to restore your encrypted files, we urge you to do It by trying the alternative method for file recovery below. They are specifically designed to help you recover at least some of the encrypted files. You can find them in step “2. Restore files encrypted by .master Ransomware”.

Note! Your computer system may be affected by .master Ransomware and other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of threats such as .master Ransomware.
Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter’s malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

To remove .master Ransomware follow these steps:

1. Boot Your PC In Safe Mode to isolate and remove .master Ransomware files and objects
2. Find files created by .master Ransomware on your PC

Before starting the Automatic Removal below, please boot back into Normal mode, in case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.

Use SpyHunter to scan for malware and unwanted programs

3. Scan for malware and unwanted programs with SpyHunter Anti-Malware Tool
4. Try to Restore files encrypted by .master Ransomware

Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share