You will find below an attempt to understand and describe the operation of CTB-Locker dropper recent malware (CTB Locker: a new massive crypto-ransowmare campaign).
more here...........http://christophe.rieunier.name/securite/CTB-Locker/CTB-Locker_analysis_en.php
more here...........http://christophe.rieunier.name/securite/CTB-Locker/CTB-Locker_analysis_en.php