1. Symantec/
  2. Security Response/
  3. PHP.CTBLocker


Risk Level 1: Very Low

March 3, 2016
August 31, 2016 7:01:50 AM
Infection Length:
Systems Affected:
Linux, Solaris, Windows
PHP.CTBLocker is a Trojan horse that encrypts files on the compromised computer and then prompts the user to purchase a password in order to decrypt them.

For more information on ransomware, see our blog:
The dawn of ransomwear: How ransomware could move to wearable devices

Note: Definitions prior to August, 2016 may detect this threat as PHP.Cryptolocker.G.

Antivirus Protection Dates

  • Initial Rapid Release version May 20, 2016 revision 034
  • Latest Rapid Release version August 30, 2016 revision 019
  • Initial Daily Certified version May 20, 2016 revision 049
  • Latest Daily Certified version August 30, 2016 revision 021
  • Initial Weekly Certified release date March 9, 2016
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yusuke Kudo

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube