Backdoor

About “Backdoor:Win32/Berbew!pz” infection

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: EB957DA2031CC44D97B5.mlw
path: /opt/CAPEv2/storage/binaries/0b0e66e9ae3ef330fa93f68da46f3a5e06aa27c1cd4d8734e894f4389a1fbd5c
crc32: 54214466
md5: eb957da2031cc44d97b59d55a7ea3097
sha1: 6b5cbe081d07746b4a31c1af6528a94b33e806ca
sha256: 0b0e66e9ae3ef330fa93f68da46f3a5e06aa27c1cd4d8734e894f4389a1fbd5c
sha512: 017db80f454e91fbf3e651dc32b1c119ced84bf266b95f002a110572ace265b048477e825ae8a561eccc47735c2da2db447b9f3d91fb5f14ff11472539b4899b
ssdeep: 6144:e71K4s5tTDUZNSN58VU5tTt50NoYnX5tTDUZNSN58VU5tTokBf7bmS:e04s5t6NSN6G5tb0fX5t6NSN6G5tTvz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1A46C47AFAB6121C257C875AC43696155D487D72FAA3D507CFF4028ABECA0842FDE83
sha3_384: 4e85bc97e7471f81ca77c0736be5e7ce01307ef4292555feb0d219e276d645c11a1ca7cfd0e4d56c8e4b2d3e6af492da
ep_bytes: 90909090609067e80000000090909090
timestamp: 2018-02-05 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Backdoor.Hangup.B
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.gh
ALYacGenPack:Backdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.QukartGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Backdoor.Hangup.B
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.C5B833A61E
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
ClamAVWin.Trojan.Crypted-29
KasperskyTrojan-Spy.Win32.Qukart.af
NANO-AntivirusTrojan.Win32.Qukart.iuarbx
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREGenPack:Backdoor.Hangup.B
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.eb957da2031cc44d
EmsisoftGenPack:Backdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
GoogleDetected
AviraTR/Spy.Qukart.NB
VaristW32/Qukart.K.gen!Eldorado
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataGenPack:Backdoor.Hangup.B
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOK!EB957DA2031C
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-Ransom.Win32.Pornoasset.a
YandexTrojanSpy.Qukart!ilrg4T3MCO4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.81d077
AvastWin32:TrojanX-gen [Trj]

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment