m.st 0 Posted August 2, 2017 Report Share Posted August 2, 2017 Hello, I think my Computer is infected by some GlobeImposter variant. I think the malware itself was removed by Windows Defender, but of course the files are still encrypted. ID Ransomware identified as GlobeImposter 2.0, but i am not sure if this is true. I tried the various globe Decrypter from your website, but it seems like drag and drop is not working, I always get the message "Reference file is missing..." (depending on the version of the decrypter i tried), but i did drag and drop the reference file AND the encrypted file to the decrypter .exe. As required I started EEK and FRST. I will add FRST.txt and Addition.txt and also an encrypted file and the reference file, also the HOW TO file from the ransomware, maybe it helps. Many thanks in advance. Schulkind-Kreis-Stern-2017.afdesign Schulkind-Kreis-Stern-2017.afdesign.crypt.{[email protected]}.BRT92.{[email protected]}.BRT92 FRST.txt Addition.txt #HOW_DECRYPT_FILES#.html Quote Link to post Share on other sites
kygiacomo 2 Posted August 2, 2017 Report Share Posted August 2, 2017 did u only have windows defender running? i have emsisoft internet security and so far i have stayed safe from all ransomware,malware and virus's..i have paired Emsisoft with zemana and i could not be happier..i highly suggest once u get this problem fixed to look into emsisoft software..gl man Quote Link to post Share on other sites
Fabian Wosar 390 Posted August 4, 2017 Report Share Posted August 4, 2017 There is, unfortunately, no known way to decrypt files encrypted by GlobeImposter2 that doesn't involve the cooperation of the ransomware authors. Sorry, but you will have to restore your latest backups. Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.