CryptorBit and HowDecrypt Information Guide and FAQBy Lawrence Abrams on February 13, 2014 @ 02:27 PM | Last Updated: February 27, 2014 | Read 113,874 times.
Table of Contents
BleepingComputer.com was one of the first support sites to have reports of the CryptorBit, or HowDecrypt, ransomware. At the time, though, we were unable to help as this infection has been incredibly elusive and any supposed samples would not work. Recently, a member known as DecrypterFixer, has been able to recover some files that were supposedly encrypted by this malware. Due to our ability to now help users with this infection we have put together a guide that contains all known information about the CryptorBit infection.
All of this information has been compiled from reports by victims and consultants who contributed to our over 31 page CryptorBit support topic. Big thanks to everyone who contributed, especially DecrypterFixer, Piglet 65, Dalicar, Cody Johnston, and Happy Heretic for their assistance in working on the repair process. This guide will continue to be updated as new information or approaches are gathered. If you have anything that you think should be added, clarified, or revised please let us know in the support topic linked to below.
CryptorBit is a ransomware program that was released around the beginning of December 2013 that targets all versions of Windows including Windows XP, Windows Vista, Windows 7, and Windows 8. When infected, this ransomware will scan your computer and encrypt any data file it finds regardless of the file type or extension. When it encrypts a file, it will also create a HowDecrypt.txt file and a HowDecrypt.gif in every folder that a file was encrypted. The GIF and TXT files will contain instructions on how to access a payment site that can be used to send in the ransom. This payment site is located on the Tor network and you can only make the payment in Bitcoins.
When CryptorBit modifies your files it is actually not encrypting the entire file, but rather corrupting it by replacing the first 512 bytes of the file. What it appears to be doing is copying the first 512 bytes of the file's original file header, encrypting those bytes, and storing them at the end of the file. It will then create a different 512 byte header and replace the file's normal header with it. This effectively corrupts the file because a program that would normally open this type of file would see an unknown header and not be able to open it. The good news is that a technique has been found that can repair the file's header and thus allow you to recover your corrupted files.
As for the registry and file paths this infection is using, not much is known at this time. We have not been able to acquire a working dropper or samples that will run and thus can't give definitive information on what files and registry entries it creates. What we do know is that it will create random files and folders under the %AppData%, %LocalAppData%, or %ProgramData% system folders. It will also create HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce entries to start the infection when Windows starts.
Another component that is commonly bundled with CryptorBit is a cryptocoin miner. This component will utilize your computer's CPU to mine digital coins, such as Bitcoin or other coins, for the malware developer that will then be deposited into their wallet. This generates further revenue for the malware developer.
Unfortunately, no dropper for this infection has been actively seen in the wild at this time. Victim's reports indicate that their files had become corrupted right after installing a fake Flash update or being infected by a rogue anti-virus program of some sort. At this time, none of these reports have been corroborated.
If you find that you are infected with CryptorBit it is suggested that you automatically scan your computer with an antivirus or antimalware program. We have seen that many antivirus vendors are able to detect the infection files and clean them. As these files are widely detected by AV programs, it has been discussed that this infection may actually be installed remotely by someone hacking into a server or computer. This would allow them to disable any AV programs, install the encrypter, encrypt your files, and then clean up the installer. This would also explain why no one has been able to find the installer for this infection. With that said, make sure you change your passwords on your computer and if you use remote desktop, please consider changing your remote desktop port as described in the following tutorial:
The first method is to try and restore your files from a backup. If a backup is unavailable, then you should attempt to restore your files from Shadow Volume Copies. Windows XP Service Pack 2 and higher utilize a feature called Shadow Volume Copies that, if enabled, automatically create backup copies of some your data files for you. For more information on how to restore files via the Shadow Volume Copies, please see this section of the guide:
If a backup does not exist and you are unable to restore from the Shadow Volume Copies, then there is still good news! A BleepingComputer.com member named Nathan Scott, aka DecrypterFixer, has come up with a program that will allow you to recover JPG, PST, MP3, PDF, .DOC, .XLS, .XLSX, .PPTX, .and DOCX documents that have been encrypted by CryptorBit. To use DecrypterFixer's tools, please use the link below:
If you had System Restore enabled on the computer, Windows creates shadow copy snapshots that contain copies of your files from that point of time when the system restore snapshot was created. These snapshots may allow us to restore a previous version of our files from before they had been encrypted. This method is not fool proof, though, as even though these files may not be encrypted they also may not be the latest version of the file. Please note that Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, & Windows 8.
In this section we provide two methods that you can use to restore files and folders from the Shadow Volume Copy. The first method is to use native Windows features and the second method is to use a program called Shadow Explorer. It does not hurt to try both and see which methods work better for you.
Using native Windows Previous Versions:
To restore individual files you can right-click on the file, go into Properties, and select the Previous Versions tab. This tab will list all copies of the file that have been stored in a Shadow Volume Copy and the date they were backed up as shown in the image below.
To restore a particular version of the file, simply click on the Copy button and then select the directory you wish to restore the file to. If you wish to restore the selected file and replace the existing one, click on the Restore button. If you wish to view the contents of the actual file, you can click on the Open button to see the contents of the file before you restore it.
This same method can be used to restore an entire folder. Simply right-click on the folder and select Properties and then the Previous Versions tabs. You will then be presented with a similar screen as above where you can either Copy the selected backup of the folder to a new location or Restore it over the existing folder.
You can also use a program called Shadow Explorer to restore entire folders at once. When downloading the program, you can either use the full install download or the portable version as both perform the same functionality.
When you start the program you will be shown a screen listing all the drives and the dates that a shadow copy was created. Select the drive (blue arrow) and date (red arrow) that you wish to restore from. This is shown in the image below.
To restore a whole folder, right-click on a folder name and select Export. You will then be prompted as to where you would like to restore the contents of the folder to.
Nathan Scott, aka DecrypterFixer, has developed tools that can fix various types of files that have been encrypted by CryptorBit. Currently his tools can recover corrupted PST, JPG, PDF, MP3, DOC, and XLS files. In order to use his tool you must have Microsoft Net Framework 4.0 or higher installed on your computer. If you using Windows XP, you will need to have service pack 3 installed before you can install Net 4.0. If you find that his tools have helped you recover your files, please feel free to send him a tip using one of the methods below:
Once the file has been downloaded, extract the zip file, and run the Anti-CryptorBit.exe program. This will open the main dashboard for Anti-CryptorBit as shown below.
Simply click on the recovery method that you wish to run and follow the instructions. If you need any help with Anti-CryptorBit please post your questions in the CryptorBit support topic.
When you are infected with CryptorBit, the infection will create HowDecrypt.txt and HowDecrypt.gif files that contain information on how to pay the ransom. Below is the contents of the HowDecrypt.txt and HowDecrypt.gif messages:
The instructions tell the victim that in order to pay the ransom they need to install a special program called Tor. Once Tor is installed they can use it to access their hidden web site at the TOR address 4sfxctgp53imlvzk.onion. When a user visits that address using the Tor browser they will be shown a page that gives instructions on how to pay Bitcoins in order to receive a CryptorBit decryptor. The current cost for the decryptor as of 02/13/2014 is .6 BTC.
In order to submit the payment you will need to first enter the Personal Code from your HowDecrypt.txt files. The site will report back how many bitcoins you need to send as your ransom payment. Once you send the bitcoins to the requested address and fill in the rest of the information, you will supposedly be sent a CryptorBit Decryptor program. I have no first-hand knowledge of anyone paying the ransom and have not seen the decryptor. Based on the payments sent to known CryptorBit Bitcoin addresses, though, quite a few people appear to have paid the ransom.
Previous CryptorBit Decryptor Purchase page screenshots:
CryptorBit allows you to pay the ransom by sending bitcoins to an address shown in the CryptorBit Decryptor Purchase page. Bitcoins are currently worth over $600 USD on some bitcoins exchanges. CryptorBit has used different bitcoin payment addresses for those who were infected. Some of these addresses are below:
You can use the links above to see transactions into the wallet and out of the wallet. You can typically tell which payments to this address are from ransom victims as there will be many payments with the same amount.
02/13/14 - Initial guide creation
This is a self-help guide. Use at your own risk.
BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can ask for malware removal assistance in our Virus, Trojan, Spyware, and Malware Removal Logs forum.
If you have any questions about this self-help guide then please post those questions in our Am I infected? What do I do? and someone will help you.
|Tech Support Forums | The Computer Glossary | RSS Feeds | Startups | The File Database | Virus Removal Guides | Downloads|