Trojan

What is “Trojan-Downloader.Win32.Buerak.bk”?

Malware Removal

The Trojan-Downloader.Win32.Buerak.bk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Buerak.bk virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

appnoder11113.info

How to determine Trojan-Downloader.Win32.Buerak.bk?


File Info:

crc32: 78C528F8
md5: d9c64a5e7e3dd6aece2ae1dadba56b8f
name: buer_2020-02-14_11-30.exe
sha1: e898639ea0f46754acd5d9102145e09602341ba7
sha256: 934e5538341e13807b5a173776e947596814f9dd2fd179e8373d70f2b6170b24
sha512: 317bbcbca132cfe33c84628af0765139c3b0c93c6f2f9b7e3047c378b64727eb40087e3a869e9014591cb126d7cf7a7e53e1ae183deab26755dfffdfbc87c097
ssdeep: 3072:L1H4FdrzyEnk9bc+8aN+nfz3yIg6+U8Wozy1WZ:5oXk9b2zfz3hdL8n21W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0115 0x0099

Trojan-Downloader.Win32.Buerak.bk also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Siggen9.11886
MicroWorld-eScanTrojan.GenericKD.33280076
FireEyeGeneric.mg.d9c64a5e7e3dd6ae
McAfeeArtemis!D9C64A5E7E3D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056094f1 )
BitDefenderTrojan.GenericKD.33280076
K7GWTrojan ( 0056094f1 )
Cybereasonmalicious.ea0f46
TrendMicroTROJ_GEN.R057C0DBG20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
GDataTrojan.GenericKD.33280076
KasperskyTrojan-Downloader.Win32.Buerak.bk
AlibabaTrojanDownloader:Win32/Buerak.cdcf0198
ViRobotTrojan.Win32.Z.Win.244736
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan-downloader.Buerak.Wuha
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.BuerLoader.byhxg
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Emotet.dt
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33280076 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.YYQR-1873
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.BuerLoader.byhxg
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Glupteba.DHI!MTB
ArcabitTrojan.Generic.D1FBD04C
ZoneAlarmTrojan-Downloader.Win32.Buerak.bk
AhnLab-V3Trojan/Win.MalPe.X2054
Acronissuspicious
ALYacTrojan.GenericKD.33280076
Ad-AwareTrojan.GenericKD.33280076
MalwarebytesTrojan.MalPack.GS
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.HBCT
TrendMicro-HouseCallTROJ_GEN.R057C0DBG20
RisingTrojan.Obfuscated!1.9A68 (CLOUD)
FortinetW32/Malicious_Behavior.VEX
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Downloader.c5c

How to remove Trojan-Downloader.Win32.Buerak.bk?

Trojan-Downloader.Win32.Buerak.bk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment