Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jun 2021

How to remove CTB Locker virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

CTB Locker virus – ransomware that has been targetting the USA, Germany, Italy, and the Netherlands mostly

CTB Locker cyber threat

CTB Locker virus (also found under a title of CTB-Locker ransomware) is a crypto-type [1] malware, which started attacking PC users in the middle of July 2014. According to research, this malware strain has been found targetting users in USA, Germany, Italy, and the Netherlands. It is almost identical to Cryptowall virus, Cryptolocker, Cryptorbit, Critroni, etc., so if you have ever heard about any of these parasites, you will know what this ransomware is used for. Basically, it is designed for encrypting specific data files and then making people pay for their decryption. In most cases, people who want to recover access to their photos, videos, and other files are asked to pay $300. Besides, CTB-Locker ransomware loads AllFilesAreLocked.bmp, DecryptAllFiles.txt, [seven random letters].html, or similar messages/files to report about the data encryption process.

Name CTB Locker virus
Type Ransomware
Danger level Very high. Can cause important data losses
Targets People who reside in Germany, USA, Italy, and the Netherlands
The start This infection first took place in 2014
Similar malware Cryptowall virus, Cryptolocker, Cryptorbit, Critroni
Ransom notes AllFilesAreLocked.bmp, DecryptAllFiles.txt, [seven random letters].html
Malware detection Use anti-malware to scan the entire system and detect malicious objects
Repair Rely on PC repair tools like FortectIntego and fix virus damage

CTB Locker virus, of course, demands a ransom price that should be paid in a form of Bitcoins [2]. If you think that your PC has already infected by this ransomware virus, the first thing that you should notice is that you cannot reach your files anymore. Also, you may start seeing a warning message explaining the whole thing and asking to pay a fine.

In this case, you should immediately scan your computer with a reputable anti-spyware program because the sooner you do that, the larger amount of files you could save. Unfortunately, this CTB Locker virus can hardly be noticed before it starts showing its notification that reports about encrypted data and asks to pay a ransom.

That's why you should always have an updated anti-spyware installed on your computer that could easily help you to prevent infections like this one. For that, we highly recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Also, this is a very beneficial program to search for malware traces when opting for automatic removal.

CTB Locker virus

You need to remove the virus immediately after you spot files that are encrypted and do not load properly. This type of threat has been getting more and more advanced each year and targetting a bigger audience. Continue reading this article and find out all updates on this ransom-demanding threat.

Additionally, note that when infected with CTB Locker ransomware, you can lose files with such extensions:

3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx, etc

The start of 2015: CTB-Locker starts urging for a ransom of 3 BTC 

CTB-Locker was renewed at the beginning of 2015. After this, the virus started asking to pay 3 BTC or about $2774 for giving people an opportunity to recover the connection to their files. Also, it includes “free decryption” service, an extended deadline (96 hours) to pay the fine, and an option that allows changing the language of the ransom message.

At the moment of writing, victims can switch from English to Dutch, German and Italian [3]. An interesting thing is that this new version of CTB Locker allows people to select 5 different files for free decryption. This option is called “Test Decryption” and is presumably given to convince users that this service is not invented.

Nevertheless, you should NEVER pay this ransom and support scammers. Just scan your computer with reliable anti-spyware and remove the virus. Then, you should download one of these programs that are given down below to recover the connection to your files.

CTB Locker ransomware

2016 update: CTB-Locker ransomware starts attacking websites 

It seems that 2016 can be called the year of CTB Locker. According to the latest news, hackers have started using this virus to attack websites. Beware that “CTB Locker for websites” can easily replace your original index page to the affected webpage. Also, it can encrypt all scripts, documents, photos, databases, and other important files, and start displaying its warning on the main page of the affected website.

According to the latest reports, the CTB-Locker virus can hold the site for as long as it makes its owner pay a ransom. To unlock it and decrypt encrypted files, a victim of this ransomware has to pay a ransom of $150 or £100. Also, the virus lets its victim see how the decryption process works and provides 2 decryption keys to unlock two random files.

The latest victim is the British Association for Counseling & Psychotherapy website [4]. People can't reach this domain, which now shows a detailed guide explaining how the owner of this site has to pay the fine and get encrypted files back. Of course, money is what scammers are expecting to get. To avoid a need to pay a ransom for hackers, you should create A BACKUP for your OS and the most important data.

RAUM method helps to spread the virus

According to the latest news, CTB-Locker has started spreading with the help of a new system called RAUM. This newly presented strategy is used to infect the most popular torrent files with ransomware, an infamous Dridex, Pony, and similar malware that is launched right after the malicious torrent file is installed on the system.

If infected with CTB Locker, you will discover that your files with these extensions are encrypted: .ai, .cdr, .doc, .docx, .eps, .jpg, .xls, .ppt, .psd, .pdf, etc. RAUM [5] is believed to work as a pay-per-install system that tracks torrent users first to find out which torrent files are the most popular ones among them.

Next, it infects these files with malware and uses hacked accounts to upload malicious content on the system. Security researchers have already discovered that hackers have been using Pirate Bay and Extra Torrent sites. Make sure you stay away from these domains to protect yourself and your files.

CTB Locker malware

The year 2017: Crooks released a fake version of CTB-Locker named CTB-Faker

CTB-Locker has become a target of amateur hackers who have made a version of CTB-Faker — a program that looks like CTB-Locker but is not the actual infection [6].

A ransom note that this fake ransomware drops on the infected computers looks identical to the original virus version and notifies the victim that his/her computer has been infected with CTB-Locker and they have to pay 50 USD to recover their files.

However, for the data encryption CTB-Faker utilizes WinRAR functionalities, which is an easier and simpler way to achieve file encryption. The targeted files are simply compressed and stored in an archive protected with a password that hackers have selected.

Luckily, experts have already managed to dig up a vulnerability in this virus and disclosed this password — the virus-generated archives can be unlocked using the p4w1q3x5y8z code. 

However, not all imposters can be decontaminated that easily. 2017 can bring programs that are equally dangerous to their malicious counterparts and may corrupt the system just as bad. So, we can only advise you to be careful out there!  

Ransomware infections reach their target via email spam

According to experts from Virusai,[7] ransom-demanding threats are often injected into executables or Word documents that come attached to email messages. Email spam travels throughout the Internet sphere and reaches users frequently. The best way to protect yourself from malicious letters is NOT to open any questionable email received.

Additionally, if you are curious about opening an attachment, you should use an antivirus tool and scan the file/document before launching it. If something malicious is hiding there, you will be warned by your anti-malware and be able to delete the malware-laden content on time before anything bad occurs.

Nevertheless, you should always keep a distance from piracy networks, gambling, online dating, movie-streaming, game-playing, and adult-themed websites. Note that malicious payloads can come injected into hyperlinks, and suspicious-looking banner ads, pop-ups, pop-unders, and coupons.

CTB Locker removal guidelines on Windows system

If you are desperate, and you need a guide that could help you to remove virus from your computer, you are in the right place. If it has already hijacked your system, you should disconnect your computer from the Internet ASAP. Unfortunately, but we cannot give you a CTB Locker decrypter yet because it is just in the development stage. However, you should follow the step-by-step guide given below and finish the elimination of this ransomware.

Moreover, do not try to carry out the removal process on your own as even more damage might be caused! You might miss some malicious components and the infection might start running malicious processes right after the next computer boot. Note that anti-malware tools are more trustworthy at these tasks as they can complete multiple actions very fast: scan the system, detect malicious software, remove the threats.

Did this guide help?

15 comments

  1. Fleur

    Contrary to whats mentioned above: The CTB Locker will also encrypt dropbox files. If you have synced your computer with dropbox, your files will appear encrypted on the dropbox server soon enough. Hence; it is not enough to have dropbox as your only backup.. We had this problem and have not found a solution to restore our (dropbox) files yet..

  2. Selvi G

    My personal files are encrypted with the CTB locker, can any one help.
    Contact number: +91-8105586478

  3. jEM

    can my files get recover then

  4. Farhad

    Dear sir, My pc was infected with ctb-locker and my file became encrypted. then I formated my C drive and I thought the virus may clean. but unfortunately after reinstallation of windows my files in my D drive was the still encrypted. Now the solution you posted in this page is not applicable in my newly installed windows OS. What will be the solution for my case???

    A beneficial advise my be highly appreciated.
    Best regards

  5. Shankar

    My personal files are encrypted with the CTB locker, can any one help.
    Contact number: +91-8391821124

  6. vikas

    Dear sir, My pc was infected with ctb-locker and my file became encrypted. then I formated my hdd drive and I thought the virus may clean. but unfortunately after reinstallation of windows my files in my D drive was the still encrypted. Now the solution you posted in this page is not applicable in my newly installed windows OS. What will be the solution for my case???and my all data loss , solution data recovery , help me

    A beneficial advise my be highly appreciated.
    Best regards

  7. FRAJ

    Please Help me how to save my encrypted file please help me 8801840317337

  8. Mel

    One of my friends connected his iPhone to my laptop to play songs thru iTunes. I suspect he had infected files on his phone that got moved to my laptop - which now has CTB Locker.

    Malwarebytes "discovered" a lot of files, but did not eradicate CTB Locker.

  9. johndoe

    First of all people the virus can be removed from your computer and your files can be recovered there are hidden under a folder not visible to you at the time. Although he is informative on the history of viruses. Think about it. if you were trying to actually help with this isssue.. Name the program that your using . give credit to the developers of the software by naming them since its really them who did it not you. your just telling people you found a program that works and passing of as a IT specialist.

  10. Jeffrey

    CTB encrypts everything it can find. It would be good to correct that in the instructions above. We were able to reverse the virus by rolling back (Rollback Rx) - similar to Windows system restore.

  11. Scott

    I am a professional photographer. A few weeks ago my computer was attacked by CTB-LOCKER the one with the black screen and code KEY. Proven Data Recovery has been able to identify the VARIENT of the virus I have. It is - RSA-2048 CTB-Locker encryption virus.
    They want 2,600 for the decryption of 300 image files that this virus has encrypted on a SD CARD. The computer still reads close to 900mb of data on the card and I have been told by multiple sources that there is a chance my images are still there, but I have had no luck and its going to take me quite some time to come up with this money so in mean time I am exploring other options and learning more about computers and code than I would otherwise have never cared to.
    It angers me to no end that people can actually even do this. That they can hurt total strangers in this away. Hurt their jobs. Effect their lives just for the sake of doing so and then dangle our data in front of us so we freak out and jump. I refuse to pay this RANSOM and it is frustrating to no end that the supposed GOOD GUYS want WAY THE HELL MORE!! Its very backwards to me and does not seem right. It is almost impossible to get a simple strait answer from people in this area and there is a lot of double talk and I have bad a couple people remote access my computer and I see them try things even I have tried.
    The files that are blocked were never on my hard drive. I didnt even have time to make a hard copy. One moment they were find and the next they were encrypted. I have done 2 system restored and a factory restore and computer has updated protection but the files remain locked on my card.
    Is there any effective decryption for CTB-LOCKER - RSA-2048 CTB-Locker encryption virus
    What are the odds? Is it even worth saving all this money for these people? He did ID the variant. Even that came as a shock. Its all I have to go on. Maybe, if you think you have a solution for me of course I would be willing to work put pay arrangement but I would need to see at lest SOME proof. Maybe do one or two that I can see. There are 300 on the card and I am really quite desperate for this material, or to be told convincingly and enough times that all hop is lost. I am not at that point yet.
    Thanks for your time
    Sincerely

    Scott Str8onthe8@yahoo.com

  12. maahnaz

    hi, Im from iran.my personal pictures are encrypted with the CTB locker.i use the method1 for windows7 and i inestall spyhunter4 and scan my computer. it found 78 threats. and need to " fix threats". and that need to be registry with credit card. unfortunately i dont have a credit card. what can i do? please help me.

  13. Severine

    SpyHunter removed this virus, thanks GOD! However, my files are left encrypted, however, I am not going to pay the CTB Locker ransom. Theres no way I am supporting these cyber criminals. Screw them!

  14. descarcons

    does anybody know how to decrypt the files??! please help! i have removed the virus but i need to get my files back!

  15. Mrc

    I dont know if it is the same for Dropbox, but in OneDrive, there is a version history, in which you can restore your files to previous versions - which are stored online for quite some time.

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.