TL30Z ransomware can encrypt photos, videos, documents, and databases, making them useless

TL30Z ransomware is a variant of Snatch ransomware family that was detected back in 2018. It has file locking capabilities. By using complicated encryption algorithms,[1] it can lock users' personal files, like photos, videos, and documents. The files are appended with the .tl30z extension.
So if a file was previously named picture.jpg, after encryption, it would look like this – picture.jpg.tl30z. The icons are also changed to blank pages, so thumbnails are unavailable. The affected data cannot be opened or used in any way. If users do not have backups, ransomware infections can result in permanent data loss.
| NAME | TL30Z |
| TYPE | Ransomware, cryptovirus, data-locking malware |
| MALWARE FAMILY | Snatch ransomware |
| FILE EXTENSION | .tl30z |
| RANSOM NOTE | DECRYPT_TL30Z_FILES.txt |
| DISTRIBUTION | Infected email attachments, “cracked” software installations, software vulnerabilities |
| FILE RECOVERY | If no backups are available, recovering data is almost impossible. We list alternative methods that could help you in some cases below |
| ELIMINATION | Scan your machine with anti-malware software to eliminate the malicious files (this will not recover your data) |
| SYSTEM FIX | Malware can seriously tamper with Windows systems, causing errors, crashes, lag, and other stability issues. To remediate the OS and avoid its reinstallation, we recommend scanning it with the FortectIntego repair tool |
The ransom note

The full DECRYPT_TL30Z_FILES.txt ransom note reads as follows:
Hello!
All your files are encrypted, write to me if you want to return your files – I can do it very quickly!
Contact me by e-mail:
repairdb@seznam.cz or repairdb@mail.frThe name of the letter must contain an encryption extension
Do not rename encrypted files, you may lose your files permanently.
You may be a victim of fraud. Free decryption as guarantee.
Send us up to 3 files for free decryption.
The total size of files must be less than 1 Mb! (non archived), and files should not contain valuable information. (databases,backups, large excel sheets etc.)
!!! Do not turn off or restart the NAS equipment. This will result in data loss !!!
The ransom note rushes people to pay the ransom as soon as possible. Cybercriminals say that if users pay, they will get a decryption tool that will recover their files. However, we strongly advise against paying the ransom or contacting threat actors because they cannot be trusted.
Usually, they choose cryptocurrencies as a form of payment because they provide anonymity. Once you send a cryptocurrency transaction to another wallet, it is impossible to get it back. You can not only lose your data forever but your money too. It is not worth that risk as threat actors often ask for a significant amount of money.
Distribution methods
There are multiple channels that cybercriminals use to spread ransomware. Most of the time, people infect themselves because they are not careful enough when browsing the web. One of the most popular infection methods is “cracked” software[2] installations. It can happen on Torrent websites, peer-to-peer file-sharing platforms, and other unsafe download sources.
They are the perfect breeding ground for all kinds of malware. It is impossible to know if the packages users are downloading contain any malicious files. It is best only to use official web stores and developer websites. Even though it can get costly, people may save in the long run by keeping their system running smoothly.
Another popular infiltration entry is through email. Crooks can use social engineering methods[3] to construct convincing messages. Usually, they will try to trick people into downloading infected attachments or clicking on malicious links. We recommend not opening any email attachments unless they come from someone you know.
Start the removal process
The important thing to do is to disconnect the affected machine from the local network as we talked about the dangers of that previously. For home users, disconnecting the ethernet cable should do the job. If this happened at your workplace, doing that might be complicated, so we have instructions for corporate environments at the bottom of this post.
If you try to recover your data first, it can result in permanent loss. It can also encrypt your files the second time. It will not stop until you remove the malicious files causing it first. You should not attempt removing the malicious program yourself unless you have experience. Manual removal of ransomware is extremely complicated and is suitable for people with advanced IT skills.
Use anti-malware tools like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to scan your system. This security software should find all the related files and entries and remove them automatically for you. In some cases, malware does not let you use antivirus in normal mode, so you need to access Safe Mode and perform a full system scan from there:
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. – it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.
- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.

- Go to Advanced options.
- Select Startup Settings.
- Click Restart.
- Press 5 or click 5) Enable Safe Mode with Networking.

Repair corrupted system files
Performance, stability, and usability issues, to the point where a full Windows reinstall is required, are nothing unusual after malware infection. These types of viruses can alter the Windows registry database, damage vital bootup, and other sections, delete or corrupt DLL files, etc. Once a system file is damaged by malware, antivirus software cannot fix it.
Manual troubleshooting of such damage is also very complicated and can take a long time. This is why FortectIntego was developed. It can fix a lot of the damage caused by an infection like this. Blue Screen errors, freezes, registry errors, damaged DLLs, etc., can make your computer completely unusable. By using this maintenance tool, you could prevent yourself from having to reinstall WIndows completely.
- Download the application by clicking on the link above
- Click on the ReimageRepair.exe
- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process
- The analysis of your machine will begin immediately
- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

Try recovering data with third-party software
Only hackers hold the decryption key,[4] which can unlock your files, so if you did not back them up previously, there is a good chance that you will never get them back. You can try using data recovery software, but keep in mind that third-party programs cannot always decrypt the files. Whatever the situation may be, we suggest at least trying this method. Before you proceed, copy the corrupted files and place them in a USB flash drive or another external storage device. And remember – only do this if you have already removed the TL30Z ransomware.
Before you begin, several pointers are important while dealing with this situation:
- Since the encrypted data on your computer might permanently be damaged by security or data recovery software, you should first make backups of it – use a USB flash drive or another storage.
- Only attempt to recover your files using this method after you perform a scan with anti-malware software.
Install data recovery software
- Download Data Recovery Pro.
- Double-click the installer to launch it.
- Follow on-screen instructions to install the software.

- As soon as you press Finish, you can use the app.
- Select Everything or pick individual folders where you want the files to be recovered from.

- Press Next.
- At the bottom, enable Deep scan and pick which Disks you want to be scanned.

- Press Scan and wait till it is complete.
- You can now pick which folders/files to recover – don't forget you also have the option to search by the file name!
- Press Recover to retrieve your files.

Was this guide helpful?
Be the first to comment