TROJ_CRYPCTB.P
Ransom:Win32/Critroni.A(Microsoft), Trojan.Cryptolocker.E(Norton), Win32/Filecoder.DA trojan(Eset)
Windows

Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
Downloaded from the Internet
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be dropped by other malware.
It uses Windows Task Scheduler to create a scheduled task that executes the dropped copy.
It connects to certain websites to send and receive information.
TECHNICAL DETAILS
765,440 bytes
EXE
Yes
06 Feb 2015
Connects to URLs/IPs, Encrypts files, Displays graphics/image, Displays message/message boxes
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be dropped by the following malware:
Step 3
Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.
Step 4
Restart in Safe Mode
Step 5
Search and delete this file
- %All Users Profile%\Application Data\{random characters}.html
- %All Users Profile%\Application Data\{randomly selected folder }\{random file name}
- %User Profile%\My Documents\!Decrypt-All_Files-{random letters}.bmp
- %User Profile%\My Documents\!Decrypt-All_Files-{random letters}.txt
- %System%\config\systemprofile\My Documents\!Decrypt-All_Files-{random letters}.bmp
- %System%\config\systemprofile\My Documents\!Decrypt-All_Files-{random letters}.txt
- %Windows%\Tasks\{random file name}.job
Step 6
Reset your Desktop properties
Step 7
Restart in normal mode and scan your computer with your live casino online product for files detected as TROJ_CRYPCTB.P. If the detected files have already been cleaned, deleted, or quarantined by your live casino online product, no further step is required. You may opt to simply delete the quarantined files. Please check this for more information.
NOTES:
Restore the encrypted files by this malware from backup. Note that the encrypted files have the extension .{7 random letters}.