Backdoor

Backdoor:Win32/Berbew!pz removal tips

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: F682E603CEA8AB8D8565.mlw
path: /opt/CAPEv2/storage/binaries/2f9a8e0b88e4c562baca461a65c68b7e4f29febcafa87e2c285d1bf730a372c5
crc32: 4BBE6952
md5: f682e603cea8ab8d8565a1f2c2dd6d94
sha1: a9758d80e48d34d5c0301930c7937f35db986119
sha256: 2f9a8e0b88e4c562baca461a65c68b7e4f29febcafa87e2c285d1bf730a372c5
sha512: bccd6bc7a0ec0ffe1983d1449150552d68292186650a741cdbdc84b66155d67d3515de3b185ae34e97ac1c271f183c7f733e2b8db544e975e63aeb6ad4d59a48
ssdeep: 768:sqWPSsN+rLcbdLIeoMkSGOaarmVsEFY8YrJbvhSaYFc/1H5oVEYmrUTvn93b7NRQ:YPhNoM3OsQ6Th/h+VsEn9rjDHE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107536BC7628A0E71F04303711EDB4199A13A656523F9B4F082F4935F12BEE4D3AB9E76
sha3_384: 6738ca06a82521eac4261cfc0e075096c9ee446f4fb9fa34df6f57288e70712e0026656d64092330002223e83510f6c0
ep_bytes: 609090909090b800104000906a049090
timestamp: 2031-10-15 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Backdoor.Hangup.B
FireEyeGeneric.mg.f682e603cea8ab8d
SkyhighBehavesLike.Win32.Generic.kh
McAfeeTrojan-FVOJ!F682E603CEA8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Qukart.Win32.1951395
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.59e8e7ac
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.0e48d3
ArcabitGenPack:Backdoor.Hangup.B
BitDefenderThetaAI:Packer.6EA8E45C21
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.HangUp.jxkkmy
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
EmsisoftGenPack:Backdoor.Hangup.B (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREGenPack:Backdoor.Hangup.B
TrendMicroTROJ_GEN.R002C0DHI23
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Qukart.ahel
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=82)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.FNZL9N
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGenPack:Backdoor.Hangup.B
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DHI23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Spy.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment