Backdoor

How to remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 51C8EAD3E68A60C6842A.mlw
path: /opt/CAPEv2/storage/binaries/f31a2f99ac4ecaec98d7b6da5501842eb29a63a2ac014d54ec28e1924647a8bd
crc32: 9416B131
md5: 51c8ead3e68a60c6842a0bb8e46676d7
sha1: e8d93f5c45a240b3f6a5a1d6ce691f9f7ec4fa58
sha256: f31a2f99ac4ecaec98d7b6da5501842eb29a63a2ac014d54ec28e1924647a8bd
sha512: 82ec12d5720059862f53e167c4133af6d90265fe3103c203b98dd7db9a9d69af7e38c6919ae3b2ab4e594047744806565b21618f267bfb7ee1a978fed8af32f4
ssdeep: 1536:NxY1mX0whiqRAOM1xRSwHhWJqtccDccmccDccDcc4cc4cc4cc8SccccccccccMcZ:bLU1HhU4ccDccmccDccDcc4cc4cc4cc/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178539D1BA6410EB0C52372F3188B0EE1B3B989A9037D8C91147770DE2767AEE6476F57
sha3_384: 30b3ee0d049a95765f2a2c6cb50b0c4bfcb9197d569cf9f701200b46f543e1c062d1124b3fe578622e68f75f661932e4
ep_bytes: 609090b80010400090906a049090905f
timestamp: 2031-10-15 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Backdoor.Hangup.B
SkyhighBehavesLike.Win32.Generic.kh
ALYacGenPack:Backdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Backdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.c45a24
ArcabitGenPack:Backdoor.Hangup.B
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jxrpmt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
EmsisoftGenPack:Backdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.51c8ead3e68a60c6
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Qukart.ajay
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=88)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.FNZL9N
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!51C8EAD3E68A
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Spy.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.2EB7E01921
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment