Ransom

About “Ransom:Win32/Necne” infection

Malware Removal

The Ransom:Win32/Necne is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Necne virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ransom:Win32/Necne?


File Info:

crc32: A0B2A24D
md5: 2d46e68b6e9f3983a40932e6ee1cdf53
name: 2D46E68B6E9F3983A40932E6EE1CDF53.mlw
sha1: c8c439cfb5439325fc8bf91938c2d2714c5da4f0
sha256: 7b81f2a98819a1ec50b67ba171586e6bd59abcb11baca0c6554eb0fae2850d44
sha512: 59acf69c3f938d1cddc276b97662a1fe3d18ebee3df9f8b2087eb60fee08b325baa2b278c74ba1b3cd6e12eb1c052a6aa81ebac66d8ff72524628290f60f6e8e
ssdeep: 1536:Oci+8UluOXSC5liawrEDKyzirwQu8PfPY8O:Oc18OuOXSC5liaFDu0uHO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Necne also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005031101 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24858
CynetMalicious (score: 100)
ALYacTrojan.Ransom.GlobeImposter
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005031101 )
Cybereasonmalicious.b6e9f3
CyrenW32/GlobeImposter.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FV
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.GlobeImposter.2D743939
NANO-AntivirusTrojan.Win32.Filecoder.ewthac
ViRobotTrojan.Win32.Ransom.56832.I
SUPERAntiSpywareRansom.Filecoder/Variant
MicroWorld-eScanGeneric.Ransom.GlobeImposter.2D743939
Ad-AwareGeneric.Ransom.GlobeImposter.2D743939
SophosML/PE-A + Troj/Ransom-EVE
ComodoTrojWare.Win32.Necne.AB@7l2s58
BitDefenderThetaGen:NN.ZexaF.34608.deW@aqV68b
TrendMicroRansom_FAKEGLOBE.SMB
McAfee-GW-EditionGenericRXDU-FO!2D46E68B6E9F
FireEyeGeneric.mg.2d46e68b6e9f3983
EmsisoftGeneric.Ransom.GlobeImposter.2D743939 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117723
eGambitUnsafe.AI_Score_62%
MicrosoftRansom:Win32/Necne
ArcabitGeneric.Ransom.GlobeImposter.2D743939
AegisLabTrojan.Win32.Generic.4!c
GDataGeneric.Ransom.GlobeImposter.2D743939
AhnLab-V3Trojan/Win32.Globeimposter.C2185487
Acronissuspicious
McAfeeGenericRXDU-FO!2D46E68B6E9F
MAXmalware (ai score=99)
VBA32Trojan.Encoder
MalwarebytesRansom.FileCryptor
TrendMicro-HouseCallRansom_FAKEGLOBE.SMB
RisingRansom.GlobeImposter!1.A538 (CLASSIC)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.FV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Necne.HxMBt48A

How to remove Ransom:Win32/Necne?

Ransom:Win32/Necne removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment