Globe2 Ransomware

What is Globe2 Ransomware?

Globe2 Ransomware, as its name may suggest, is the new version of Globe Ransomware that first appeared last year, in 2016. Although this ransomware program can encrypt hundreds of file extensions and cause severe devastation on your system, just like in the case of the first version, you can actually decrypt your files using a free tool. But this should not mislead you to think that you can take this threat lightly; it is still a dangerous ransomware threat that needs to be taken care of immediately. On the other hand, if you are not an experienced or advanced computer user, we do not even recommend that you yourself try to find this free decryption tool or use it, either. It is best to find a computer savvy friend or even a professional to help you with that. In any case, our malware specialists at anti-spyware-101.com say that you should remove Globe2 Ransomware as soon as possible.

Where does Globe2 Ransomware come from?

Believing that a spam filter can weed out all malicious or spam mails, and separate them from legitimate and important mails is a big mistake. As a matter of fact, spam filters do make mistakes and may let real spam land in your inbox while they may misplace important mails and put them in your spam folder due to high level of strict policies. Of course, a lot of users know that it is best to check the spam folder because some expected e-mails can show up there. This is why the spam e-mails these cyber criminals use may appear to be important so that they can draw your attention and make you want to open them.

The problem is that such a mail does not really contain any useful information; it simply instructs you to view the attached file or to download it by clicking the provided link. However, this attachment is the malicious executable file that will infect your system and encrypt your precious files. This obviously means that normally you could not possibly survive this attack without losing your files, even if you managed to delete Globe2 Ransomware. This is only pure luck that in this case you can use a free tool to recover your files. This is why this should serve as a big lesson. Preventing such dangerous threats from being able to infiltrate your system should be your priority. You can protect your PC, for example, by keeping your browsers and drivers always updated so that Exploit Kits cannot harm you. Remember that once such a ransomware sneaks onto your system, you cannot delete it without serious consequences in most cases.

How does Globe2 Ransomware work?

This ransomware infection can attack hundreds of file extensions and encrypt your photos, documents, saved games, and so on. The encrypted files get a new, seemingly random, file name and extension similar to this "DBNMnwlpI3TOjg.abc." This threat places a ransom note file called "Read me please.hta" in every affected folder. This note claims that all your files have been encrypted and you have to write an e-mail to "support-decoder@india.com" or via Bitmessage (an encrypted P2P communications protocol) and send the ID you can find in the note. You have to contact your attackers within 48 hours to get a reply message that is supposed to inform you about the Bitcoin address where you have to transfer 1 BTC, which was worth $700 a year ago but is worth currently a whopping $17,240. Obviously, you should not even think about transferring this money and not only because a free tool already exists to decrypt your files. We recommend that you remove Globe2 Ransomware right away.

How can I delete Globe2 Ransomware?

If you follow our guide below, you can relatively easily eliminate this threat. Once you remove Globe2 Ransomware, you can apply the free decryptor to recover your files. If, for whatever reason, you could not find or apply it, you can also use your backup you may have in cloud or stored on a removable drive. If you would like to defend your PC properly, it may be time for you to decide to install a reliable anti-malware program like SpyHunter.

Remove Globe2 Ransomware from Windows

  1. Press Win+R and type regedit. Click OK.
  2. Remove "HKCU\Software\Globe" registry key.
  3. Exit the editor.
  4. Press Win+E.
  5. Delete the malicious file in %LOCALAPPDATA%. This file has a default .exe icon and may be named "trust.exe".
  6. Delete all the ransom note files ("Read me please.hta") from every affected folder.
  7. Empty your Recycle Bin.
  8. Restart your computer. 100% FREE spyware scan and
    tested removal of Globe2 Ransomware*
Disclaimer
Disclaimer

Leave a Comment

Enter the numbers in the box to the right *