Backdoor

What is “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: AFBA2A33F9664DFA0F6B.mlw
path: /opt/CAPEv2/storage/binaries/a1e90647f37ebac5e0a9e6e64a46fc8492504765c408413755c673696a1f44d8
crc32: 413C8227
md5: afba2a33f9664dfa0f6b0a14257e8d44
sha1: 22649418d276eb8f41564bf08d7c6c1c9045806a
sha256: a1e90647f37ebac5e0a9e6e64a46fc8492504765c408413755c673696a1f44d8
sha512: 6077439a92f8c00aad704e68fabe0b5a964b5d7b933854181d76f066828e4f10e2224e5cd2b11ffe8f1d93d6b77fa55b7377141d2d04087b1ba7250349861e82
ssdeep: 768:KAV+ebrwP63lthMLJihpzNrWuddsalqr0YvYwM17kgMKq/Z/1H5TC5nf1fZMEBFN:jV+J61tyJihpVhdqa5lwKMzl+NCyVso
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127434AEEAD9B29D2CD5B0BB53FB544D1B238486903A5301167DCA039FB5A33C4B6A70D
sha3_384: ec358361819b9076721b63604d08c5c04aaef65e0ea7600f662e68524182939a23ff95cafe130a1dce3454e2914c0b87
ep_bytes: 90909090609090b800104000bbf87e40
timestamp: 2023-07-29 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-29
FireEyeGeneric.mg.afba2a33f9664dfa
SkyhighBehavesLike.Win32.Generic.qh
ALYacBackdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitBackdoor.Hangup.B
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
SophosMal/Padodor-A
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREBackdoor.Hangup.B
Trapminemalicious.high.ml.score
EmsisoftBackdoor.Hangup.B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Qukart.hy
GoogleDetected
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=81)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataBackdoor.Hangup.B
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!AFBA2A33F966
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.6CDB3E0D1E
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.8d276e
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment