Bitcoin Forum
May 13, 2024, 07:28:58 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: CTB-Locker ransomware virus!  (Read 1337 times)
spartak_t (OP)
Legendary
*
Offline Offline

Activity: 1960
Merit: 1176


@FAILCommunity


View Profile WWW
February 02, 2015, 12:21:09 PM
 #1

Hey guys,

Currently I am dealing with one PC which was infected by this virus. CTB-Locker explained by Kaspersky. There is EXTREMELY high possibility some people to post links (of wallets for example) to files infected by this virus (because it is also demands for payment in bitcoin). Currently there is NO WORKING solution of the problem and believe me.. this one is nasty. ALWAYS check what you are downloading!

Cheers,
Spartak


1715585338
Hero Member
*
Offline Offline

Posts: 1715585338

View Profile Personal Message (Offline)

Ignore
1715585338
Reply with quote  #2

1715585338
Report to moderator
1715585338
Hero Member
*
Offline Offline

Posts: 1715585338

View Profile Personal Message (Offline)

Ignore
1715585338
Reply with quote  #2

1715585338
Report to moderator
1715585338
Hero Member
*
Offline Offline

Posts: 1715585338

View Profile Personal Message (Offline)

Ignore
1715585338
Reply with quote  #2

1715585338
Report to moderator
Bitcoin addresses contain a checksum, so it is very unlikely that mistyping an address will cause you to lose money.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715585338
Hero Member
*
Offline Offline

Posts: 1715585338

View Profile Personal Message (Offline)

Ignore
1715585338
Reply with quote  #2

1715585338
Report to moderator
1715585338
Hero Member
*
Offline Offline

Posts: 1715585338

View Profile Personal Message (Offline)

Ignore
1715585338
Reply with quote  #2

1715585338
Report to moderator
1715585338
Hero Member
*
Offline Offline

Posts: 1715585338

View Profile Personal Message (Offline)

Ignore
1715585338
Reply with quote  #2

1715585338
Report to moderator
azguard
Legendary
*
Offline Offline

Activity: 1484
Merit: 1001


Crypto-News.net: News from Crypto World


View Profile
February 03, 2015, 06:59:34 AM
 #2

10x for the information i will remember the name and if i found some solution will post it here also if you find some solution post it here.



              ▄▄▄██████▄▄▄
          ▄██████████████████▄
       ▄████████████████████████▄
 ▄▄  ▄████████████████████████████▄
███████████████████████████████████▄
 ▀▀█████████████████████████████████▄
   ██████████████████████████████████
   ██████████████████████████████████
   ██████████████████████████████████
   ██████████████████████████████████
   ▀████████████████████████████████▀
    ▀██████████████████████████████▀
     ▀▀██████████████████████████▀
        ▀██████████████████████▀
           ▀▀▀████████████▀▀▀
.
.....
.....
.....
.....
.....
.....





dsattler
Legendary
*
Offline Offline

Activity: 924
Merit: 1000


View Profile
February 03, 2015, 07:01:21 AM
 #3

I recommend to check every downloaded zip before extracting with virustotal.com!

Better be safe than sorry!!!

Bitcointalk member since 2013! Smiley
b!z
Legendary
*
Offline Offline

Activity: 1582
Merit: 1010



View Profile
February 03, 2015, 07:19:57 AM
 #4

There was a news article on it last year: http://www.coinbuzz.com/2014/07/29/ctb-locker

It's still quite relevant
dsattler
Legendary
*
Offline Offline

Activity: 924
Merit: 1000


View Profile
February 03, 2015, 07:29:39 AM
 #5

There was a news article on it last year: http://www.coinbuzz.com/2014/07/29/ctb-locker

It's still quite relevant

That thing is really bad. Better you have a recent backup!!!

Bitcointalk member since 2013! Smiley
spartak_t (OP)
Legendary
*
Offline Offline

Activity: 1960
Merit: 1176


@FAILCommunity


View Profile WWW
February 03, 2015, 10:50:41 AM
 #6

There was a news article on it last year: http://www.coinbuzz.com/2014/07/29/ctb-locker

It's still quite relevant

I know about that virus since Cryptolocker. This one is nastier than ever and it seems that his last modification is from January this year. It is impossible to decrypt the files, because of the cryptography used in the virus.

spartak_t (OP)
Legendary
*
Offline Offline

Activity: 1960
Merit: 1176


@FAILCommunity


View Profile WWW
February 03, 2015, 10:52:43 AM
 #7

10x for the information i will remember the name and if i found some solution will post it here also if you find some solution post it here.

Well... as far as I remember the virus was first spotted in July, 2014. Old modification still has no solution so you can imagine how serious is the problem. Smiley

There was a news article on it last year: http://www.coinbuzz.com/2014/07/29/ctb-locker

It's still quite relevant

I know about that virus since Cryptolocker. This one is nastier than ever and it seems that his last modification is from January this year. It is impossible to decrypt the files, because of the cryptography used in the virus.

dsattler
Legendary
*
Offline Offline

Activity: 924
Merit: 1000


View Profile
February 03, 2015, 04:12:19 PM
 #8

10x for the information i will remember the name and if i found some solution will post it here also if you find some solution post it here.

Well... as far as I remember the virus was first spotted in July, 2014. Old modification still has no solution so you can imagine how serious is the problem. Smiley

There was a news article on it last year: http://www.coinbuzz.com/2014/07/29/ctb-locker

It's still quite relevant

I know about that virus since Cryptolocker. This one is nastier than ever and it seems that his last modification is from January this year. It is impossible to decrypt the files, because of the cryptography used in the virus.


I wonder how they hide the encryption key in their code, so that nobody can extract it...  Huh

Bitcointalk member since 2013! Smiley
nomoreheroes7
Sr. Member
****
Offline Offline

Activity: 326
Merit: 250


King of all the land


View Profile
February 03, 2015, 04:57:02 PM
 #9

Just pay the ransom. Problem solved.


 Tongue
spartak_t (OP)
Legendary
*
Offline Offline

Activity: 1960
Merit: 1176


@FAILCommunity


View Profile WWW
February 03, 2015, 05:54:47 PM
 #10

I wonder how they hide the encryption key in their code, so that nobody can extract it...  Huh

CTB-Locker renames your files with 6 or 7 letters after the original file extension (example: table.xls.srbcgxz). That "srbcgxz" is actually your "ticket" for the line of people who are willing to pay the ransom and it gives you unique unlock key which is about 3 times longer that normal Windows serial number. I saw that you can buy the kit for like $3,000. I wonder what can happen if some antivirus company decide to buy the kit and crack the code. Smiley

Just pay the ransom. Problem solved.


 Tongue

Unfortunately currently this is the only way (if you don't have backup).

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!