Become a fighter against malware and join the forum at SensorsTech!  The SensorsTech’s forum is the place where you can solve your PC issues and educate yourself about malware. You are welcome to discuss various security topics with our professional team and other users like you! To unlock all features of the forums, you have to create an account. Otherwise, you can only browse the topics without taking part in the discussions. To leave a comment or ask your questions, read our Registration Agreement and create your free account here.

*

Execute

  • *****
  • 265
  • +45/-0
  • Your friendly neighbourhood IT guy
      • View Profile
.xtbl Files Virus - A New Version of Scarab Ransomware
« on: April 19, 2018, 12:43:39 pm »
Malware researchers have a new version of the notorious Scarab ransomware. According to some of them, the cryptovirus uses the AES encryption algorithm and is coded in Delphi.
The idea behind the Delphi programming usage is for it cause more infections as it might be spread to older systems, like Windows 98, others speculate.

The Scarab virus (with the .xtbl extension) creates the following mutexes:

  • ShimCacheMutex
  • STOPSCARABSTOPSCARABSTOPSCARABSTOPSCARABSTOPSCARAB

The Scarab ransomware deletes Shadow Volume Copies and some System Backups via commands.

You can read more about the threat from the following article:

.xtbl Files Virus (Scarab Ransomware) – Remove and Restore .xtbl Files

*

never

  • *****
  • 121
  • +24/-0
  • Network Administrator and Malware Researcher
      • View Profile
Re: .xtbl Files Virus - A New Version of Scarab Ransomware
« Reply #1 on: April 19, 2018, 01:35:31 pm »
Hello, in order to provide further support, we have created the following video, which contains manual and automatic removal instructions within it. Do not hesitate to ask us any questions by commenting here or under the video itself.

https://youtu.be/2hrNbk1xNb8


*

Martin

  • *
  • 18
  • +6/-0
      • View Profile
Re: .xtbl Files Virus - A New Version of Scarab Ransomware
« Reply #2 on: April 19, 2018, 04:34:53 pm »
Delphi programming language? Pathetic! :D

*

Execute

  • *****
  • 265
  • +45/-0
  • Your friendly neighbourhood IT guy
      • View Profile
Re: .xtbl Files Virus - A New Version of Scarab Ransomware
« Reply #3 on: April 19, 2018, 05:03:09 pm »
Pathetic, but it works. And it is quite clever to be honest.