Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Strange Ransomware Behavior

  • Please log in to reply
3 replies to this topic

#1 Nordic PC

Nordic PC

  • Members
  • 3 posts
  • Local time:05:22 PM

Posted 28 October 2014 - 02:22 PM

Hello all,

  I've got a client that called this morning unable to open some PDFs, DOCs, JPGs, and XLSs. I found that they have been encrypted, but no other signs of a virus are there. It all happened back on 9-15. It crawled their mapped drives in addition to their user folder.


  What's strange is I can't find any HOW_DECRYPT.txt files or anything like that. Nor were there any changes to the background, or pop up windows asking for a ransom. It's entirely possible that their AV blocked the main payload, but somehow the encryption thread got going, but that's rather unlikely.


  Anyways, has anyone seen something like this before? I have a couple samples if you would like to compare them to other variants of Cryptolocker. I did try uploading to the Fireeye Fox-it guys, but the site said it wasn't Cryptolocker.


Thanks for the info in advance,



BC AdBot (Login to Remove)


#2 PuReinSAniTY


  • Members
  • 432 posts
  • Gender:Male
  • Location:in a basement
  • Local time:07:52 AM

Posted 29 December 2014 - 06:04 AM

That isn't normal for ransomware do you have the scan logs for the antivirus. Usually the ransomware would have a decryption process... Well find the scan logs see what it detected and try to find the file that the av detected and upload it to virus total so you can have a better understanding of what you are dealing with and then post a topic in the virus/spyware malware Trojan removal forums.

they call me te java mayster

#3 Sintharius


    Bleepin' Sniper

  • Members
  • 5,639 posts
  • Gender:Female
  • Location:The Netherlands
  • Local time:11:22 PM

Posted 29 December 2014 - 06:10 AM

You will need elevated help if it's indeed a ransomware infection... I will ask a Moderator to transfer your thread.

#4 quietman7


    Bleepin' Janitor

  • Global Moderator
  • 51,769 posts
  • Gender:Male
  • Location:Virginia, USA
  • Local time:06:22 PM

Posted 29 December 2014 - 06:57 AM

These infections are created to alert victims and demand a ransom payment. Please look in your documents folder for an image the malware normally uses for the background note....it may be labeled "decryptallfiles" or something similar. If you don't find it there, check the quarantine logs for your anti-virus and any other security tools you may have used. If you still don't find anything, then most likely it is CTB Locker which we have found often fails to leave a note.

A repository of all current knowledge regarding CTB Locker and Critroni Ransomware is provided by Grinler (aka Lawrence Abrams), in this tutorial: CTB Locker and Critroni Ransomware Information Guide and FAQ

Reading that Guide will help you understand what CTB Locker (Critroni) does and provide information for how to deal with it. The newest variants of CTB Locker typically encrypt all data files and rename them as a file with a 6-7 length extension with random characters. At this time there is no fix tool and no way to retrieve the private key that can be used to decrypt your files without paying the ransom.

More information in this article: New Critroni variant offers free test decryption and now uses CTB2 extension. Unfortunately, there is still no known method of decrypting your files without paying the ransom.

There is also an ongoing discussion in this topic: CTB Locker or DecryptAllFiles.txt Encrypting Ransomware. Rather than have everyone start individual topics, it would be best (and more manageable for staff) if you posted any questions, comments or requests for assistance in that topic discussion.

The BC Staff
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users