Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2020

How to remove GLB ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

GLB ransomware – a new cryptovirus variant from the Dharma family

GLB ransomware

GLB ransomware is a cryptovirus that encrypts[1] all non-system files on an infected device and tries to extort money for a decryption tool. This file-locking parasite originates from the Dharma ransomware family, which was first spotted in 2016 but became really active in the first quarter of 2019.

This newer variant – GLB ransomware virus, like all its former version (Cvc, SUKA, World, etc.), append a complex three-part appendix to all original filenames during the encryption process: an appointed user ID, criminals, contact email (in this case [gonald58@cock.li]), and .GLB extension. Locked files cannot be opened, thus are rendered useless until decrypted.

When all personal files, such as documents, backups, archives, etc., are locked, the virus creates two types of ransom notes – a pop-up window and loads of FILES ENCRYPTED.txt text files. Both messages from these ransom notes are displayed at the bottom of this paragraph.

name GLB ransomware
type Ransomware
Family Dharma virus
Ransom note FILES ENCRYPTED.txt scattered all over the infected computer, and a pop-up window
Appended file extension Consist of three parts – user ID, criminal contact details in brackets, .GLB extension
Criminal contact details Two emails are given to make contact – gonald58@cock.li and bank008800@cock.li
Malware removal Reliable anti-malware applications should be used to remove GLB ransomware with ease
System health Users should use system tune-up tools like the FortectIntego to scan their devices for any irregularities the cryptovirus might have caused

The text ransom notes' message is short and consists basically of two emails provided to establish contact gonald58@cock.li and bank008800@cock.li. With the pop-up window, creators of GLB ransomware explain to the victims that all their files were encrypted, and if they want to get it back, they must contact the hackers (by the same two emails as provided in the text files).

The last part of the pop-up window message is the same as in many other cryptovirus ransom notes and consists of threats to the GLB ransomware virus victims, urging them no to rename the encrypted files and not to try any third-party decryption toolkits as that may cause data to be undecryptable.

Meeting the cybercriminals' demands can lead the victims into a lose-lose situation, where they lose not only their encrypted data but also their hard-earned money. There are plenty of cases that cybercriminals didn't respond and left their victims high and dry after receiving a ransom.

That's we suggest users removing GLB ransomware from all infected devices as soon as possible. Victims can do it manually, though it requires some high-level knowledge and experience, or automatically with the help of anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.

GLB ransomware virus

Once the GLB ransomware removal is done, victims of this cyber attack should concentrate on their devices' health. We recommend using a powerful FortectIntego system tune-up tool to scan the device and fix any irregularities the cryptovirus has done to the system registry and other essential system settings.

Cybercriminals display this message in the ransom pop-up window:

YOUR FILES ARE ENCRYPTED
Don't worry,you can return all your files!
If you want to restore them, follow this link:email gonald58@cock.li YOUR ID –
If you have not been answered via the link within 12 hours, write to us by e-mail:bank008800@cock.li
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

And this short message can be found on all FILES ENCRYPTED.txt files:

all your data has been locked us
You want to return?
write email gonald58@cock.li or bank008800@cock.li 

Most common ransomware spreading techniques and how to avoid them

Cybercriminals employ many distribution methods to spread their creations, but our research shows that one of the most most common ways malware is delivered is email spam. Read this section of the article if you want to find out how to evade ransomware attacks.

We've all received spam emails. Email service providers even have a separate folder for them. Hackers send out tens of thousands of spam emails, trying to trick people into either clicking on a mischievous hyperlink that will lead to a malicious site or download an infected attachment. If any of these actions is executed, then a payload file of a virus might be downloaded, and a device infection could start within seconds.

GLB file virus

Although cybercriminals are doing their best to trick everyday internet users, you shouldn't give in. Before opening any link or downloading an attachment of a phony looking email, users should carefully look through the message itself.

Look for grammatical errors or any other irregularities. If the email looks shady, then don't open any hyperlinks, and always scan every email attachment with a reliable anti-malware application before downloading it.

Guidelines for GLB ransomware removal from infected devices

As we mentioned in the first paragraph, any malware should be eliminated ASAP. It doesn't matter if it's pesky adware[2] or GLB ransomware virus. Manually or automatically, all suspicious files, for your own safety, must be abolished from your devices as soon as they are detected. 

Victims should remove GLB ransomware with the help of professional, time-tested anti-malware software like SpyHunterCombo Cleaner and MalwarebytesMalwarebytes. However, it is possible to delete the virus manually, but honestly, who has the time to do that. Entrust it to anti-virus apps to do it swiftly and correctly.

Since cryptoviruses not only encrypt personal files but make changes to system settings, when GLB ransomware removal is finished, experts[3] recommend repairing the system registry and other essential system settings with a system repair tool like the FortectIntego app.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.