Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2018

How to remove HiddenBeer ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

HiddenBeer ransomware is a HiddenTear-based cryptovirus that demands $100 ransom

HiddenBeer is a malicious ransomware that encrypts victim's data and demands $100 for its decryption. This threat is based on HiddenTear[1] and adds .beer file extension. After the successful data-locking process, it generates the ransom note and places the message in a text file called FILES-HELP-[computer's name].TXT. The message is written in English and states about @FILE-DECRYPTER.exe file that is responsible for running a file decrypter needed to recover locked files. HiddenBeer ransomware emerged in October 2018, so there is no information on how many users have already been affected. However, the recovery after the attack is not an easy task as the threat is using a sophisticated encryption algorithm to lock your files immediately after getting on the system.

Name HiddenBeer
Type Ransomware
File extension .beer
Ransom amount $100 in BTC
Ransom note Named in a pattern FILES-HELP-[USER'S PC NAME].TXT
Encryption method AES
Contact email tr0ning@protonmail.com
Elimination Use FortectIntego for HiddenBeer ransomware removal

HiddenBeer is typical ransomware which locks photos, videos, documents, and even archives or databases to extort cryptocurrency. The ransomware attack starts when a malicious payload is downloaded to the system, and the device becomes infected. Malware then scans your computer and finds files for the encoding process. Additionally, the ransomware employs AES encryption method to perform a quick file-locking procedure which makes the affected data useless. The virus marks each file using .beer file extension and generates ransom note in a text file.

HiddenBeer ransomware ransom message is placed on every folder on the system. The text file reads the following:

<HIDDENBEER!!> 

Your files is have Been encrypted. Why have they been encrypted? To help ensure your security. Them decrypted the get the To by Our Specialists,  just the send $ 100 of the Bitcoin worth the (The BTC), to:33Lf7BrDXwNBMM4ZVg5dMQg1Bvuwzd1VQm

The send a Email afterwards to ” tr0ning@protonmail.com ” with your computer name and transaction data. 
Name Computer: HAPUBWS-the PC 
Once you have your decryption key, the Use IT in the file decrypter. 
IT is not the if the open, the go to your Desktop and the run “@ the FILE-DECRYPTER.exe” 

As many other crypto-extortion based threats, HiddenBeer ransomware demands for a ransom in Bitcoin equivalent to 100$. However, paying the ransom is not the best solution for getting your files back. It is better to remove the virus and then focus on data recovery using your backups or specially designed software.  

Many researchers[2] advise avoiding the contact with ransomware developers because paying the ransom may lead to more severe damage to the system or even privacy issues and data or money loss. 

Remove HiddenBeer ransomware using your antivirus or employ tools like FortectIntego to get rid of the threat completely. A full system scan is crucial when it comes to ransomware elimination because there is a possibility that registry changes and additional files were added by virus developers to make sure the virus is persistent and hard to terminate.

HiddenBeer ransomware removal should be performed before trying to recover files encrypted by the threat. The easiest way to perform this process is by using backups. However, if you don't have these extra copies saved on devices that the ransomware hasn't reached, you should check data recovery methods listed below the article.

HiddenBeer ransomware

Ransomware payload is hidden on safe-looking file attachments

Spam email is the most common technique used to spread ransomware and similar malware around the globe. It is quick and easy because tons of people get emails every day and users tend to open suspicious ones without paying enough attention to details. 

Such emails may look as:

  • order information from services;
  • invoices from companies;
  • official emails from government institutions.

Unfortunately, legitimate-looking MS Word or Excel file attachments may be filled with malicious macros[3] and spread all kinds of intruders on the system including the direct ransomware script. You should pay more attention to senders' name, email subject line and grammar mistakes or other misconnections between the email and file attachment. Try scanning the file before downloading on the computer.

HiddenBeer ransomware termination should be done using anti-malware tools

You need to employ reputable anti-malware tools to remove HiddenBeer ransomware from the system safely. While testing the threat, we used FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes that should perform the job perfectly. A full system scan with the help of these anti-malware tools will help you indicate malicious files, vulnerabilities or corrupted files that cannot be found manually. 

Once you take care of HiddenBeer ransomware removal, move on to recovering your encrypted files. If you can't launch the scanner to get rid of malware files, you should reboot your computer to Safe Mode with Networking to disable the malware. Follow our guidelines if you don't know how to boot into this mode before you try any of the data recovery methods. 

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.