Ransom

Generic.Ransom.GlobeImposter.CAF1AF18 removal instruction

Malware Removal

The Generic.Ransom.GlobeImposter.CAF1AF18 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.GlobeImposter.CAF1AF18 virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Appends a known encryptJJS ransomware file extension to files that have been encrypted

How to determine Generic.Ransom.GlobeImposter.CAF1AF18?


File Info:

crc32: FF0F137F
md5: b5204963231f9bddba42e611c9f09400
name: B5204963231F9BDDBA42E611C9F09400.mlw
sha1: 018166da7dce248f8a9104fa4a5f2dc20038c0e7
sha256: 8cbb405174fb7ae4cbbfefd934e5396feddd33cfdaed075ce439cc82b710c711
sha512: ec9de09cc2b83e4446d6954f8e220296b70ca3a0fb5b1e7ee01e949199dc0276413550c5adfd01ff0dd4ede7ad0bb1b24948831610a502acb35096609598eecd
ssdeep: 1536:Ad6eytM3alnawrRIwxVSHMweio3mPs5g:C6ey23alnaEIN/Wd5g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.GlobeImposter.CAF1AF18 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00502c261 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGeneric.Ransom.GlobeImposter.CAF1AF18
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00502c261 )
Cybereasonmalicious.3231f9
CyrenW32/S-0a10191d!Eldorado
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Filecoder.FV
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Globeimposter-6991673-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.GlobeImposter.CAF1AF18
NANO-AntivirusTrojan.Win32.Encoder.faecqn
ViRobotTrojan.Win32.Ransom.75776.B
MicroWorld-eScanGeneric.Ransom.GlobeImposter.CAF1AF18
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.GlobeImposter.CAF1AF18
SophosML/PE-A + Troj/Ransom-EVE
ComodoTrojWare.Win32.Necne.AB@7l2s58
BitDefenderThetaAI:Packer.CF295BD81E
TrendMicroRansom_FAKEGLOBE.SMB
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
FireEyeGeneric.mg.b5204963231f9bdd
EmsisoftGeneric.Ransom.GlobeImposter.CAF1AF18 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cblhx
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASCommon.127
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Filecoder.RB!MSR
ArcabitGeneric.Ransom.GlobeImposter.CAF1AF18
SUPERAntiSpywareRansom.FileCoder/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Ransom.GlobeImposter.CAF1AF18
AhnLab-V3Trojan/Win32.FileCoder.R228072
Acronissuspicious
McAfeeGlobelmposter!B5204963231F
MAXmalware (ai score=87)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.GlobeImposter
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_FAKEGLOBE.SMB
RisingRansom.GlobeImposter!1.A538 (CLASSIC)
YandexTrojan.GenAsa!5gkkdOe61ic
IkarusTrojan-Ransom.GlobeImposter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FV!tr
AVGWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.GlobeImposter.CAF1AF18?

Generic.Ransom.GlobeImposter.CAF1AF18 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment