What is CTB-Faker?
Type: ransomware-type virusAlert level: Severe
CTB-Faker (CTB-Locker) is distributed via fake online profiles in Adult sites that trick victims into watching a password-protected striptease video.However, the link to this “striptease video” downloads a malicious Zip archive.
Once the victim extracts this Zip file and runs the executable file, the CTB-Faker will then start encrypting victim's files. Once executed, the malicious file will display an error message claiming that victim's files have been encrypted by CTB-Locker. The private (decryption) key is supposedly mastered in remote servers controlled by cyber criminals.
Therefore, victims must pay a ransom in order to receive this key and restore these locked files.
The ransomware will leave ransom notes on the computer. The infected files are located in C:\ProgramData\index.html, C:\ProgramData\your personal files are encrypted.txt, and C:\your personal files are encrypted.txt.
