Ransom

About “Generic.Ransom.GlobeImposter.65E239B9” infection

Malware Removal

The Generic.Ransom.GlobeImposter.65E239B9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GlobeImposter.65E239B9 virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.GlobeImposter.65E239B9?


File Info:

crc32: 304A0089
md5: 86da0b9ec3b6d87cd399ecb293a78068
name: 86DA0B9EC3B6D87CD399ECB293A78068.mlw
sha1: b08e4088b505dcb880396dd87a4d1c1848bbe959
sha256: 4e19b41955717066081744ee44abcd5ff9f4d58cc72dd910696295f32d107623
sha512: c94327a48fa22593a0566a0e8e0980eb0e56d983ce6c3d17961e99381bb1fb263bebde21d57cb7757a8c7db10095eb3fe636bee8e7f3aebe078c7aa63af59c21
ssdeep: 768:rCmp945AzkfCQxmGgV5YlpJ6RIDWeRdppvO/9rjca9zsUKhb36kM:WmpTz5Qxd6m3WIw9ohb36kM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GlobeImposter.65E239B9 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.86da0b9ec3b6d87c
McAfeeGenericRXCT-NO!86DA0B9EC3B6
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00518fab1 )
BitDefenderGeneric.Ransom.GlobeImposter.65E239B9
K7GWTrojan ( 00518fab1 )
Cybereasonmalicious.ec3b6d
ArcabitGeneric.Ransom.GlobeImposter.65E239B9
CyrenW32/Ransom.HD.gen!Eldorado
SymantecRansom.GlobeImposter
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Purgen.mm
AlibabaRansom:Win32/Genasom.ali1000102
NANO-AntivirusTrojan.Win32.Purgen.esmnar
ViRobotTrojan.Win32.Ransom.69632.M
AegisLabTrojan.Win32.Purgen.tpXE
MicroWorld-eScanGeneric.Ransom.GlobeImposter.65E239B9
Ad-AwareGeneric.Ransom.GlobeImposter.65E239B9
SophosMal/Generic-R + Troj/Ransom-EVE
ComodoTrojWare.Win32.Ransom.Purgen.F@7isdzp
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Encoder.24457
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_FAKEGLOBE.SMA1
McAfee-GW-EditionBehavesLike.Win32.Infected.kt
EmsisoftGeneric.Ransom.GlobeImposter.65E239B9 (B)
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.Purgen.ba
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Ransom]/Win32.Purgen
MicrosoftRansom:Win32/Ergop.A
SUPERAntiSpywareRansom.Purgen/Variant
ZoneAlarmTrojan-Ransom.Win32.Purgen.mm
GDataWin32.Trojan-Ransom.GlobeImposter.H
AhnLab-V3Trojan/Win32.Purgen.R208326
VBA32TrojanRansom.Purgen
ALYacTrojan.Ransom.GlobeImposter
MalwarebytesRansom.FileCryptor
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Filecoder.FV
TrendMicro-HouseCallRansom_FAKEGLOBE.SMA1
RisingRansom.Purgen!1.AC62 (CLOUD)
YandexTrojan.GenAsa!LRTyx/goXF4
SentinelOneStatic AI – Malicious PE
FortinetW32/Filecoder.FV!tr
BitDefenderThetaAI:Packer.DA35B0021E
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.GlobeImposter.HxMBuFcA

How to remove Generic.Ransom.GlobeImposter.65E239B9?

Generic.Ransom.GlobeImposter.65E239B9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment