Bart ransomware virus: what it is and how to remove it
Bart ransomware (you can also find it named as Locky Bart ) is a virus that encrypts your files and asks you to pay for their decryption. This malware variant appears to be created by the same authors as Locky virus, Osiris, Thor, and Aesir.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Make sure nothing will rename more files to .bart: an automatic scan checks the PC first.
Do it yourself · free Remove Bart ransomware virus yourself 6 steps, about 18 minutes, no software needed.
Start the steps
Bart ransomware virus: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Ransom note | recover.txt; the text of the note is not in our records |
| Contact | Not recorded in our earlier report |
| Encrypted file extension | .bart |
| Decryptor | No free decryptor is known for this variant; check No More Ransom (nomoreransom.org) for updates |
| Distribution | Not recorded in the old report |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Damage | Not recorded in the old report |
|---|---|
| Name | Bart ransomware virus |
| Type | File-encrypting ransomware |
| Symptoms | Files renamed with a new extension and a ransom note left in folders |
| Evidence | 7 write-ups by security sites; no sample analysed yet |
| Encrypted files | .bart |
| Free decryptor | No free decryptor is known (checked 7 October 2026) |
| First seen | 1 February 2017 |
| Facts checked | 7 October 2026 |
- File extension:
.bart - Note file:
recover.txt
From our report of Feb 2017 · not reviewed since
More from our earlier report on Bart ransomware virus
- Surprisingly, cyber security experts from AVG and AVAST have already created the decryption software for this ransomware.
- Malware researchers from AVG and AVAST have already created free decryption tools helping victims decrypt their encrypted data for free.
How Bart ransomware virus behaves
From our report of Feb 2017 · not reviewed since
Bart ransomware virus: encrypts files without connecting to the Internet
Bart ransomware (you can also find it named as Locky Bart ) is a virus that encrypts your files and asks you to pay for their decryption.
This malware variant appears to be created by the same authors as Locky virus, Osiris, Thor, and Aesir. It has already initiated two attacks against PC users and, unfortunately, they both can be considered successful. Just like Locky, it spreads as a JS file utilizing RockLoader malware to silently download and install its infectious files on a compromised computer.
What is more, Bart virus can work and corrupt victim's files without using Internet connection, so it cannot be stopped by disabling network connection. It does not communicate with its command and control server and does not send the unique decryption key to it, but it localizes the encryption procedure and uses a slightly different technique to make files inaccessible.
Instead of encrypting them with RSA or AES encryption algorithms , ransomware puts each file into a ZIP archive and protects it with a password. It appends .bart file extension or .bart.zip file extension to the filenames, and removes the System Restore Points. The archived file name looks like this: example.txt.bart.zip. If you can find these signs of infiltration on your computer, make sure you remove Bart ransomware from the system.
Note: We have discovered that this computer threat checks default language setting before running the encryption process and in case the default language is Russian, Ukrainian, or Belorussian, the virus stops and uninstalls itself. Otherwise, it continues to run.
It is unlikely that this virus can leave any of your files unencrypted as it targets more than 160 different file types what means that all files with file extensions that this virus targets will be corrupted, including documents, photos, audio, video files and many more.
Just like any ransomware-type virus traditionally does, Locky Bart leaves a ransom note which is called recover.txt. The virus even provides several translations for the ransom note, including French, Spanish, German and Italian languages. Besides, it changes desktop background with recover.bmp image looking identical to the one that Locky virus shows.
This ransom note points the user to a payment site which can be accessed via TOR browser only. The payment site suggests Bart Decryptor for 3 BitCoins which is nearly 2000 US dollars, and that is an exceedingly big ransom price. it is worth noting that this payment site looks very similar to Locky Decryptor's one.
We do not recommend you to pay the ransom, as frauds might not provide you with the password for all these .bart.zip archives. Our suggestion is a quick Locky Bart removal. The best way to do it is to utilize an anti-malware program like .

The Bart ransomware virus ransom note
The note is called recover.txt.
We did not record the full text of the ransom note in our report.
How to remove Bart ransomware virus
Tools you'll need
All of these are free except where noted. Download them on a clean device if the infected PC is offline.
- A USB stick: to keep the ransom note, two or three encrypted files and screenshots off the infected PC.
- Microsoft Defender Offline: built into Windows 11 and Windows 10; scans before Windows starts, so running malware cannot hide.
- Microsoft Safety Scanner: a second, portable scanner with current signatures; each download works for 10 days.
- ID Ransomware: identifies the family from the note and one encrypted file and says whether a decryptor exists.
- No More Ransom: the free decryptors from police and security companies; check it again every few months.
- Fortect (optional): scans Windows for malware and repairs the system files and settings it damaged. The free scan is in the box above.
How to remove Bart ransomware virus and get your files back
Work in this order.
Disconnecting comes first, removal comes before any restore, and nothing here asks you to contact the attackers.
Step 1: Disconnect the PC and unplug backup drives
Bart ransomware virus encrypts everything it can reach, including drives and shares you connect later. Cut the network first: cable out, or Wi-Fi off from the taskbar.
Then unplug every USB stick and backup disk and pause cloud sync, so the encrypted versions do not replace your online copies. Do not reconnect any of them until the ransomware is removed from the Windows 11 or Windows 10 PC.

Windows 11: turn off Wi-Fi to take the PC offline. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 2: Save the ransom note and confirm the family
Copy
recover.txtand one or two files ending in.bartto a USB stick, and leave the originals where they are.From another device, upload the note and a sample file to ID Ransomware or No More Ransom's Crypto Sheriff, which name the family from the note, the extension and the file structure.
Write down the contact address and your personal ID from the note, because a decryptor or the police may ask for them.
Warning: Never contact the attackers from the infected Windows 11 or Windows 10 PC.

Windows 11: the ransom note and encrypted files to copy for identification. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 3: Check for a free decryptor
For Bart ransomware virus, no free decryptor is known (checked 7 October 2026). Search the family name in the No More Ransom decryption tools list and in the free decryptors of Emsisoft, Avast and Kaspersky, because new tools appear years after an attack.
Important: Keep the encrypted files even if nothing works today, and do not pay before every free option is ruled out: payment does not guarantee a working key.
Decryptors run on Windows 11 and Windows 10, but only after the ransomware itself is removed.
Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 4: Remove the ransomware before you restore or decrypt
Restoring or decrypting files while Bart ransomware virus still runs lets it encrypt them again. Run a Full scan in Windows Security > Virus & threat protection > Scan options, then the Microsoft Defender Antivirus (offline scan).
If the ransomware blocks Windows Security, start Safe Mode with Networking and scan from there. Some families install a password stealer as well, so let both scans finish on Windows 11 or Windows 10.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Look for shadow copies of the files
Open Command Prompt as administrator and run
vssadmin list shadows. If it lists copies dated before the attack, right-click a folder with encrypted files in File Explorer, choose Properties > Previous Versions, and open or restore a version from before that date.ShadowExplorer, a free tool, shows the same copies when the tab is empty or hidden. Most current families delete shadow copies, so an empty list is normal, but the check takes two minutes on Windows 11 or Windows 10.

Windows 11: vssadmin list shadows shows whether shadow copies exist. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 6: Restore the files from a backup or recover deleted originals
Restore from an external backup, File History or OneDrive's version history, choosing a date before the attack. Connect the backup drive only after the scans are clean, or the ransomware encrypts it too.
If there is no backup, file recovery software can sometimes find the deleted originals, because some ransomware writes an encrypted copy and deletes the original file.
Stop writing to the drive and try recovery on Windows 11 or Windows 10 before new files overwrite the space.
Full procedure with screenshots: Recover deleted files (Recycle Bin, backups, OneDrive) On uGetFix
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Manual removal using Safe Mode
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.

- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.
- Go to Advanced options.

- Select Startup Settings.

- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.

Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.

- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.

- Go back to the process, right-click and pick End Task.

- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.

- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.

- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
From our report of Feb 2017 · not reviewed since
Decrypting files with .Bart.zip extension
This malware is an exceptionally strong variant of ransomware, because creators of Locky know what they are doing very well.
They have already created one of the most successful and uncrackable computer virus in the history of malware what means their new virus is likely to be as strong as the previous one. . You will need one original file and one corrupted variant of it to retrieve the password of these .bart.zip archives. Do not forget to remove Bart virus from computer before you start the decryption process!
Speaking of other ransomware variants, the only possible way to recover lost files is to import them from a backup, sadly, not many people care to create them on time.
If you do not have backups, but if you want to learn how to create them, please read this article - How to backup your files? If you have a backup, you should remove the virus first and then plug in the storage device into your PC to import files.
From our report of Feb 2017 · not reviewed since
Bart malware versions
Bart v2.0 ransomware.
Since malware researchers have managed to create Bart decryption tool, criminals have upgraded the ransomware and released an undecryptable version which does not add files to archives but encrypts them instead. This version has not been cracked yet, and it is not possible to recover files for free.
The virus adds .bart2 file extensions to encrypted files and asks to pay a ransom. It places a ransom note on user's PC that informs where the user can purchase the Bart decrypter.
Perl ransomware virus. The latest version of Bart ransomware hardly differs from its second version. The most noticeable difference is that it adds different file extensions to encrypted files - it renames them by adding .perl file extension.
Reportedly, virus asks for a different sum of money from individual victims. Its ransom note also points users to Bart decrypter's payment site; however, you should not support criminals by paying them. Unfortunately, files encrypted by .perl file extension virus cannot be decrypted.
From our report of Feb 2017 · not reviewed since
Bart distribution methods
This virus spreads via malicious email campaigns that deliver a .zip file attachment.
Typically, authors of this ransomware send emails with a subject Photos. Files attached to these malicious emails are titled as image.zip, picture.zip, photos.zip and similarly. These archives carry JavaScript code, and if the user launches it, it immediately downloads and installs RockLoader malware which is an intermediary loader.
This malware downloads Bart virus and runs it. The easiest way to avoid infecting your PC with ransomware is to stay away from suspicious emails that come from unknown people or companies, and of course, keep the computer protected by installing the anti-malware software on it.
From our report of Feb 2017 · not reviewed since
Bart removal guide
Please bear in mind that Bart virus is an extremely dangerous virus and that you cannot remove it manually unless you are a skilled IT expert.
As we have said, this virus uses RockLoader malware to infiltrate the system. It has to be removed as well to forget about further problems related to this ransomware. Therefore, the best solution for Bart ransomware removal is running a full system scan with a powerful anti-malware application.
We have no doubts that this ransomware will try using various techniques to prevent its elimination from your computer. If you can't remove Bart virus because it keeps blocking your anti-spyware, follow instructions prepared by 2spyware security experts.
[GI=method-1]If you can't launch your anti-spyware because of Bart virus, you need to reboot your computer to Safe Mode with Networking and try again. Make sure you run two scans - scan when you are in Safe Mode and a full system scan when you are in a normal mode.
[GI=method-2]If Safe Mode with Networking option fails to work for you, you can also try System Restore. For that, use these steps:
It is a well-known tool which has been widely-used by PC users to revive lost files.
Use Windows Previous Versions feature to recover files encrypted by Locky Bart virus
If you had System Restore function enabled on your computer before infiltration of this ransomware, you can try recovering the most useful files with Windows Previous Versions feature. For that, follow these steps:
Use Bart decrypter to get your files back
These tools can be downloaded from here: Bart decrypter, Decryption Tool for Bart.
Report it and recover your files
Report it
Report the attack even if you do not expect the files back: insurers and banks ask for the report number, and police use the contacts in the note to link cases.
- United States
- FBI IC3 · FTC ReportFraud
- United Kingdom
- Report Fraud (formerly Action Fraud) · NCSC
- Australia
- ReportCyber (ASD)
- EU countries
- Europol: national reporting sites
Give the victim ID, the note and the date the files were encrypted. A business that holds personal data may also have to notify its data protection authority, in the EU within 72 hours.
Protect the files you restore
Restore only after the scans are clean and the PC no longer shows files that end in .bart and no longer open; otherwise the restored copies can be damaged again.
Then build a backup that survives the next infection:
- one copy in the cloud with version history
- one on an external drive that is disconnected between backups
- the working copy on the PC
Version history matters because a backup that syncs damaged files overwrites the good ones.
How to do this with the tools built into Windows: the 3-2-1 backup rule on Windows.
Choose a proper web browser and improve your safety with a VPN tool
Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.
One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.
However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.
Lost your files? Use data recovery software
While some files located on any computer are replaceable or useless, others can be extremely valuable.
Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:
- power cuts
- Blue Screen of Death errors
- hardware failures
- crypto-malware attack
- even accidental deletion
To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.
Questions about Bart ransomware virus
Is there a decryptor for .bart files?
That depends on the family behind the .bart extension, which this guide cannot confirm yet from the reports alone. Check No More Ransom and ID Ransomware with your ransom note and one encrypted file; they list families with free tools.
If none exists today, keep the encrypted files and a copy of the note on a separate drive, because decryptors are sometimes published months later after flaws are found or servers are seized. Never buy a decryptor from a website that is not the security company that made it.
How do I open .bart files?
You cannot open them by renaming or by choosing another program. The .bart ending shows that Bart ransomware virus encrypted the content, and only the matching key can reverse it. Renaming a file back to .docx or .jpg changes nothing except the icon, and it can confuse a future decryptor, so leave the names as they are.
To get the content back, use a backup, an unencrypted copy elsewhere, or a decryptor listed on No More Ransom if one exists for Bart ransomware virus. Store the encrypted files on an external disk until then.
Should I pay the ransom?
We advise against it, and so do the FBI, Europol and national cyber agencies. Payment does not guarantee a working tool: some attackers never reply, some tools damage files, and some variants have no decryptor at all. Paying also funds further attacks and can make you a target again.
Before considering payment, try every recovery option in this guide and report the attack. Companies must involve their legal adviser and insurer, because payments to sanctioned groups can be illegal. If files are truly irreplaceable, store the encrypted copies and wait; decryptors sometimes appear later.
Can a data-recovery company decrypt my files for a fee?
Only if a decryptor already exists or the company pays the attackers for you. Some "ransomware recovery" services advertise that they can decrypt families with no known flaw; in practice they negotiate with the attackers and add their own fee. Others use the same free tools listed on No More Ransom.
Before you hire anyone, ask in writing how they will recover the files, whether they will contact the attackers and what happens if they fail. A legitimate service answers clearly. If a free decryptor exists for your family, you can run it yourself.
How did Bart ransomware virus get on my computer?
The way Bart ransomware virus spreads has not been documented yet, so look at your own recent activity. On home PCs, ransomware most often comes with cracked programs, game cheats, key generators and fake updates, or with an e-mail attachment that was opened. On business networks, attackers usually log in through Remote Desktop with a stolen or guessed password.
Think back to what was downloaded or installed in the days before files that end in .bart and no longer open, and check the Downloads folder and Installed apps sorted by date. Keep anything suspicious for your report, but do not run it again.
Did Bart ransomware virus steal my files or passwords?
We do not know yet. Nothing published so far shows data theft by Bart ransomware virus, but the only confirmed sign is files that end in .bart and no longer open, which says nothing about what happened before. Many current ransomware attacks copy files or run a password stealer first, so it is wise to act as if they did.
From a clean device, change the passwords that were saved in the browsers on this PC, starting with e-mail and banking, sign out of all sessions and turn on two-step verification. Watch bank statements and account activity for the next few weeks.
Is Bart ransomware virus the same as other ransomware with a similar name?
Not necessarily. Ransomware names come from the file extension, the note or a word in the code, so unrelated families often end up with similar names, and one family can appear under several names. The difference matters: a decryptor or advice for one family does not fit another and can damage files.
Compare the ending added to your files and the exact name of the note with the summary table at the top of this guide, then upload the note and one encrypted file to ID Ransomware from a clean device. If the result names another family, follow the guide for that family instead.
Can I delete recover.txt?
Yes, the note itself is harmless text and deleting it does not affect your files. Keep at least one copy first, outside the infected PC. recover.txt contains your personal ID and the attackers' contact details, which identification services use to tell which family encrypted your files, and which a decryptor may need later.
Police reports also ask for it. Once you have saved a copy, you can remove the notes from every folder after the ransomware program has been removed and your files are restored or backed up.
My files got .bart overnight. What happened?
Ransomware often runs at night or when the PC is idle, so the encryption finishes before anyone notices. It usually entered earlier through a cracked program, a fake installer, an e-mail attachment or remote desktop with a weak password.
The .bart extension marks every file it reached. Start by disconnecting the PC from the network, then identify the family from the ransom note and one encrypted file, check for a decryptor, and look for copies in backups and OneDrive before you consider anything else.
Will Fortect remove Bart ransomware virus?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Bart ransomware virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Malwarebytes Labs: Locky Bart ransomware and backend server analysis (read October 7, 2026)
- AVAST Software page: Free Ransomware Decryption Tools (read October 7, 2026)
- CISA: StopRansomware (read October 7, 2026)
- No More Ransom (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)