The MBR ransomware is downloaded and installed by a Trojan of the Oficla family. When you reboot after it overwrites the MBR you are presented with the screen below. The claim that all the hard drives were encrypted is a lie and you don't have to go to their web site for a password. The password "aaaaaaciip" restores the original MBR so that Windows will start again on all affected systems.
Avira detects the malware as TR/Ransom.Seftad.A. The malicious boot sector is detected as "BOO/Seftad.A".