Trojan

How to remove “Trojan:Win64/Beerish”?

Malware Removal

The Trojan:Win64/Beerish is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Beerish virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

mangroveforests.com
iplogger.org
www.bing.com
ip-api.com

How to determine Trojan:Win64/Beerish?


File Info:

crc32: 23BF96F4
md5: 99d2b47944863176734dadcd6c9c36b2
name: wotsuper3.exe
sha1: a18f720155d856493c6d6213a8a358ad09c0ff97
sha256: dadbd88ae2cc84f73306eccb3356ea8431111bff3f178b35c0e35a0225b0c003
sha512: d4f2a4428d739c815730017fa7bd56a99c69413b08a27de3f9a7ffe431900c031716d8b4471d3d2412f0b9eea516f009b938baac32f44873b6b6efcb1aabc0ef
ssdeep: 12288:pANwRo+mv8QD4+0V16mSo/ty7rwRZJsZYFsgj+uzYpkbNoVQfmfIyiIm/+EZR:pAT8QE+k1J/Q7aPYYZNzYpU28m0L2QR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: wotsuper
FileDescription: wotsuper 2.1 Installation
FileVersion: 2.1
Comments:
CompanyName: wotsuper
Translation: 0x0409 0x04e4

Trojan:Win64/Beerish also known as:

MicroWorld-eScanTrojan.GenericKD.42841002
FireEyeGeneric.mg.99d2b47944863176
Qihoo-360Win32/Trojan.3a2
McAfeeArtemis!99D2B4794486
CylanceUnsafe
AegisLabTrojan.Win32.Chapak.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42841002
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.155d85
TrendMicroTROJ_GEN.R002C0DCE20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.42841002
KasperskyTrojan.Win32.Chapak.ejuk
AlibabaTrojan:Win32/Kryptik.3beb619e
ViRobotTrojan.Win32.Z.Rypack.662528
TencentMalware.Win32.Gencirc.10b8ad88
EmsisoftTrojan-Dropper.Agent (A)
F-SecureTrojan.TR/AD.VidarStealer.dhtfz
DrWebTrojan.Siggen9.20262
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.moderate.ml.score
SophosMal/RyPack-A
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.IRLE-6919
WebrootW32.Trojan.Gen
AviraTR/AD.VidarStealer.dhtfz
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D28DB3AA
ZoneAlarmTrojan.Win32.Chapak.ejuk
MicrosoftTrojan:Win64/Beerish
AhnLab-V3Malware/Win32.Generic.C3733562
BitDefenderThetaGen:NN.ZexaF.34100.DuW@aizXCadG
MAXmalware (ai score=82)
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HBWN
TrendMicro-HouseCallTROJ_GEN.R002C0DCE20
RisingTrojan.Kryptik!8.8 (CLOUD)
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.A!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq

How to remove Trojan:Win64/Beerish?

Trojan:Win64/Beerish removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment