Hey you,

35,000 ransomware infections per month and you still believe you are protected?

Sign up to receive:

  • alerts
  • news
  • free how-to-remove guides

of the newest online threats - directly to your inbox:

Grand_car@aol.com Virus Remove and Restore .XTBL Files

shutterstock_253413775Another variant of the many Troldesh ransomware variants leaving the e-mail Grand_car@aol.com has been detected in the wild. The ransomware virus is reported to use an advanced AES encryption algorith with 128-bit strength, the decryption for which is reported to be next to impossible. The ransomware has been reported to spread via several multiple ways by ESG malware researchers. It may also drop a ransom note where it may leave instructions on how to decrypt user files after the affected users pay a ransom payoff, which is usually in BitCoin. We advise you to read this article to learn how to remove Grand_car@aol.com Ransomware from your computer and restore your encrypted files.

UPDATE! Kaspersky malware researchers have released a Shade decryptor which can decode files encoded by the the Shade ransomware variants. Since this includes the .xtbl file extension, we have created instructions on how to decrypt your .xtbl files. The instructions can be found on the link below:
Decrypt Files Encrypted by Shade Ransowmare

Threat Summary

Name Grand_car@aol.com
Type Ransomware
Short Description A variant of the .XTBL ransomware viruses. Encrypts files with a strong encryption and drops a ransom note with payoff for decryption instructions.
Symptoms After encryption the ransomware may steal information and appends .xtbl extension after every file.
Distribution Method Spam Emails, Email Attachments, File Sharing Networks.
Detection Tool See If Your System Has Been Affected by Grand_car@aol.com


Malware Removal Tool

User Experience Join our forum to Discuss Grand_car@aol.com Ransomware.

Grand_car@aol.com Ransomware – Distribution Strategy

For it to infect users, the virus may utilize several different technologies. No matter what type of technology it uses, whether it is remove brute forcing to control the computer, Exploit Kits, JavaScript or directly inserting obfuscated executables, the infection may proceed in two main ways.

One scenario is if the user clicks on a malicious URL that may cause a browser redirect and the infection of the user PC via a JavaScript or a drive-by-download.

Another scenario is for users to open a malicious e-mail attachments that may be obfuscated from their antivirus and cause the infection. Such attachments usually exist in several different forms, but most of them resemble either Microsoft Office documents or Adobe Reader PDF files.

Grand_car@aol.com Ransomware – How Does It Work?

After the Grand_car@aol.com Ransomware has infected your computer, the virus might connect to a remote location and send the following information to the attackers:

  • Windows version.
  • IP networking information.
  • Antivirus software is installed.

Based on such information the actual payload may be dropped in concealed form that prevents detections from any antivirus software that might be installed on the user PC. The malicious files may be dropped in several Windows locations and under different names:

commonly used file names and folders

Typical to the XTBL ransomware variants is to also drop ransom note type of files in the Startup folder of Windows to make these viruses run when Windows boots up. Here is the default location of the folder:

→C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup.

In addition to having done this, the Grand_car@aol.com virus may also execute a privileged command in Windows command prompt, called “vssadmin delete shadows” that will delete the Windows Shadow Volume Copies without the user even noticing it has happened.

When it has been executed and started to encrypt files, Grand_car@aol.com ransomware may look for a pre-programmed set of file extensions that it will encode:

→ .odc, .odm, .odp, .ods, .odt, .docm, .docx, .doc, .odb, .mp4, sql, .7z, .m4a, .rar, .wma, .gdb, .tax, .pkpass, .bc6, .bc7, .avi, .wmv, .csv, .d3dbsp, .zip, .sie, .sum, .ibank, .t13, .t12, .qdf, .bkp, .qic, .bkf, .sidn, .sidd, .mddata, .itl, .itdb, .icxs, .hvpl, .hplg, .hkdb, .mdbackup, .syncdb, .gho, .cas, .svg, .map, .wmo, .itm, .sb, .fos, .mov, .vdf, .ztmp, .sis, .sid, .ncf, .menu, .layout, .dmp, .blob, .esm, .vcf, .vtf, .dazip, .fpk, .mlx, .kf, .iwd, .vpk, .tor, .psk, .rim, .w3x, .fsh, .ntl, .arch00, .lvl, .snx, .cfr, .ff, .vpp_pc, .lrf, .m2, .mcmeta, .vfs0, .mpqge, .kdb, .db0, .dba, .rofl, .hkx, .bar, .upk, .das, .iwi, .litemod, .asset, .forge, .ltx, .bsa, .apk, .re4, .sav, .lbf, .slm, .bik, .epk, .rgss3a, .pak, .big, wallet, .wotreplay, .xxx, .desc, .py, .m3u, .flv, .js, .css, .rb, .png, .jpeg, .txt, .p7c, .p7b, .p12, .pfx, .pem, .crt, .cer, .der, .x3f, .srw, .pef, .ptx, .r3d, .rw2, .rwl, .raw, .raf, .orf, .nrw, .mrwref, .mef, .erf, .kdc, .dcr, .cr2, .crw, .bay, .sr2, .srf, .arw, .3fr, .dng, .jpe, .jpg, .cdr, .indd, .ai, .eps, .pdf, .pdd, .psd, .dbf, .mdf, .wb2, .rtf, .wpd, .dxg, .xf, .dwg, .pst, .accdb, .mdb, .pptm, .pptx, .ppt, .xlk, .xlsb, .xlsm, .xlsx, .xls, .wps.Source:fileinfo.com

This is usually done to avoid any critical Windows files being encrypted and hence prevent Windows from ever starting again.

The files which are encrypted by the Grand_car@aol.com ransomware virus are left with a quite long file extension. It may either be the .xtbl or .CrySiS file extension and in addition to that it includes:

  • Unique alpha-numerical identifier.
  • The e-mail address Grand_car@aol.com.

Files that have been encoded with this file extension may look like the following example:


Grand_car@aol.com Virus – Conclusion, Removal, and File Restoration

As a bottom line, there are many variants of this virus and malware researchers feel convinced that it may be sold directly as a pack of tools for infection and distribution in the deep web forums. Not only this, but the virus is also reported to be a part of a RaaS (ransomware as a service) scheme, and it might also have various modifications, depending on each variant. Either way, researchers strongly advise not to pay any ransom asked by cyber-criminals and wait for a decrypter to be released.

To completely delete Grand_car@aol.com virus, it is strongly advisable to follow the removal instructions posted below. They along with some of the information in this article may help you locate and delete the files and objects associated with Grand_car@aol.com ransomware. In case manual removal fails or you feel like the virus is still on your computer, it is them almost a must to download and install an advanced anti-malware software on your computer or reinstall it and copy the files to another carrier.

If you want to restore your files, you may want to use the alternative tools in step “3.Restore files encrypted by Grand_car@aol.com Ransomware”. Bear in mind, that you should make copies of the encrypted files, just in case direct decryption methods damage them in a way.

Manually delete Grand_car@aol.com from your computer

Note! Substantial notification about the Grand_car@aol.com threat: Manual removal of Grand_car@aol.com requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove Grand_car@aol.com files and objects
2.Find malicious files created by Grand_car@aol.com on your PC
3.Fix registry entries created by Grand_car@aol.com on your PC

Automatically remove Grand_car@aol.com by downloading an advanced anti-malware program

1. Remove Grand_car@aol.com with SpyHunter Anti-Malware Tool
2. Back up your data to secure it against infections and file encryption by Grand_car@aol.com in the future
3. Restore files encrypted by Grand_car@aol.com
Optional: Using Alternative Anti-Malware Tools

Vencislav Krustev

A network administrator and malware researcher at SensorsTechForum with passion for discovery of new shifts and innovations in cyber security. Strong believer in basic education of every user towards online safety.

More Posts - Website

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.