Backdoor

How to remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: FA96626CAC888F861444.mlw
path: /opt/CAPEv2/storage/binaries/5a385504eb3a2af741a1baa7af54bf4e2600a0d7efe6331eb4ce2e791f312ce6
crc32: 125D3CE7
md5: fa96626cac888f8614441a56a0b88832
sha1: 71b305b177c45c42b410e4ad20e74b0650eaf8ff
sha256: 5a385504eb3a2af741a1baa7af54bf4e2600a0d7efe6331eb4ce2e791f312ce6
sha512: 1f1ee76b32d7366c6542c486f247939dc9393f312ec6bb2ad5d03ed194620248c8f621be6414c5d904334c60e6f9f62731cbbe8155ab6d89ed986b7176dedaba
ssdeep: 1536:2773cuBCExEuKh/s0cS6V3lbENein/GFZCeDAyY:27bzBtyuKJsNSK3lbENFn/GFZC1yY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110635C57714E0B63F1F301B2EB1EDFDEB336917287A9B591444080352246ABAD6FB2C6
sha3_384: 47d25c63712264625d219570610d8352f0a901a7516d3b2c49b3c76e9aad694bb52248f4769bfed5d4b37a70c795f57d
ep_bytes: 60909090909090b80010400090bbf87e
timestamp: 2027-09-06 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Hangup.B
CAT-QuickHealBackdoor.Berbew
SkyhighBehavesLike.Win32.Generic.kh
McAfeeTrojan-FVOJ!FA96626CAC88
MalwarebytesGeneric.Malware.AI.DDS
VIPREBackdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderBackdoor.Hangup.B
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.177c45
ArcabitBackdoor.Hangup.B
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyTrojan-Spy.Win32.Qukart.af
NANO-AntivirusTrojan.Win32.Qukart.kcrfbm
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
ZillyaTrojan.Qukart.Win32.2569217
TrendMicroTROJ_GEN.R03BC0DJQ23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fa96626cac888f86
EmsisoftBackdoor.Hangup.B (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
JiangminTrojanSpy.Qukart.ahax
GoogleDetected
AviraTR/Spy.Qukart.NB
VaristW32/Qukart.K.gen!Eldorado
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataBackdoor.Hangup.B
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.335DE3CA21
ALYacBackdoor.Hangup.B
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJQ23
TencentTrojan-Ransom.Win32.Pornoasset.a
IkarusTrojan.Spy.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment