Backdoor

Backdoor:Win32/Berbew!pz removal

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: CBBB7E83B4D6A7AF7E9F.mlw
path: /opt/CAPEv2/storage/binaries/69c6c9a286487699191ea4730eabae65e2f6e1ca5da7c9b6c9f8604f0dcbc076
crc32: 88EE3664
md5: cbbb7e83b4d6a7af7e9fc06742677405
sha1: 4ed4be68b672d418ccba61800482a7ca93bfb6db
sha256: 69c6c9a286487699191ea4730eabae65e2f6e1ca5da7c9b6c9f8604f0dcbc076
sha512: dbbdc824d2a27800cbeacc0b8fc621ebed561826824bdab63f2646c71742714600419a22591565206548ed26a31a644109dcfd5a67f7bafabbf81cc04975a436
ssdeep: 1536:qHYe+SAxRFKdmVbftTUH4bf++b++q++b++b++M++M++M++UW++++++++++8o++/K:q47Hf5ftTUH4blg6teso
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA435CDFDDBE0B72DDCB12B348DA17A2F235C6D713A981202599988E0356E284F7E345
sha3_384: 74bf427234d2b821eefb3915e13d33d087eebcfa35c13ee557c7adafbe39c28ada2b2a390a243b6a1f6316a5d501278a
ep_bytes: 90609090909090b800104000bbf87e40
timestamp: 2023-07-29 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
DrWebBackDoor.HangUp.43832
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.cbbb7e83b4d6a7af
SkyhighBehavesLike.Win32.Generic.qh
ALYacBackdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Qukart.Win32.2627862
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.19e852f5
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.8b672d
ArcabitBackdoor.Hangup.B
BitDefenderThetaAI:Packer.6CDB3E0D1E
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.kcncnc
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
SophosMal/Padodor-A
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
VIPREBackdoor.Hangup.B
TrendMicroTROJ_GEN.R002C0DJK23
Trapminemalicious.high.ml.score
EmsisoftBackdoor.Hangup.B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Qukart.hr
GoogleDetected
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataBackdoor.Hangup.B
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!CBBB7E83B4D6
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJK23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment