Backdoor

Should I remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: BAF6C2E107B4757B5B49.mlw
path: /opt/CAPEv2/storage/binaries/0ffbe0c3bbec4370b4bc23f11ebfde418ef3205d899784f85b155964a718aa5a
crc32: 46E3FE89
md5: baf6c2e107b4757b5b4949043a7d13f9
sha1: c8f3614c9ae3f8133b684059f67afbc4e220b88c
sha256: 0ffbe0c3bbec4370b4bc23f11ebfde418ef3205d899784f85b155964a718aa5a
sha512: 861580405a852cf1aad4ffe3e74d8f0dd3dd6cb0c567d5371bbbcbcb2fde36ceff50305c462997120fcc519b7ee4d4e59086f57cf5fe70918865e277ce0a2c50
ssdeep: 3072:JOSVryzVtcTgjMVqUR1cjENRZ9wmAOIayGsOOJF4EISi/i4gG4npAjmA39QQIcka:J3ry5tcM0R1nTZ9EaUn4yjK99QQd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174044B7761491BEEC743C2B52E1D48FEB725C029D3998793F438811F5336A6982BAF90
sha3_384: 3c78682095ab677dccfcb0ab1fa3049329a3feeb41343ad2675c409a306baaff5852ad7c65ddb70dd5b54d3d46881828
ep_bytes: 90906090909067e80000000090909058
timestamp: 2024-12-10 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Backdoor.Hangup.B
FireEyeGeneric.mg.baf6c2e107b4757b
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.ch
McAfeeTrojan-FVOK!BAF6C2E107B4
Cylanceunsafe
ZillyaTrojan.QukartGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Backdoor.Hangup.B
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
NANO-AntivirusTrojan.Win32.Qukart.kcxknn
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
EmsisoftGenPack:Backdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREGenPack:Backdoor.Hangup.B
TrendMicroTROJ_GEN.R03BC0DJU23
Trapminemalicious.high.ml.score
SophosTroj/Padodo-Gen
SentinelOneStatic AI – Malicious PE
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=83)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.6Y1WGK
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.5621D6C421
ALYacGenPack:Backdoor.Hangup.B
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Berbew
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJU23
TencentTrojan-Ransom.Win32.Pornoasset.a
YandexTrojan.GenAsa!FrLL7FUDrD4
IkarusTrojan.Spy.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c9ae3f
AvastWin32:TrojanX-gen [Trj]

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment