Backdoor

Backdoor:Win32/Berbew!pz malicious file

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 1B2E504B961BFB477F5B.mlw
path: /opt/CAPEv2/storage/binaries/a68879bba47fb45a3378a1796de7d20a27b445c94c8b2cf6d83aa3daa2040931
crc32: DF585DE4
md5: 1b2e504b961bfb477f5b2bc27d406819
sha1: d53663eb86405c1ef60812170c78016dcfa7eda5
sha256: a68879bba47fb45a3378a1796de7d20a27b445c94c8b2cf6d83aa3daa2040931
sha512: 4259f6817e99b163c6ef5154e36d759e6ece865ea55d779ea463b0e8da1d73408aa143ecff4c3dfef21ebcb5b8820eb3e22f912ac3a7f87e52367b4997936e4f
ssdeep: 1536:uaRQNMmH4sPjdBIjxiD/cq7m6Fxv+VlEn9rjDHE:ujNMmYshIT0xvolk9DHE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109536C2F738A0B61F72F087212D97652AF3B48AE13B55870A874441937DEB693E35C2D
sha3_384: c48ab280af4345cbbc6771c83a80d809c465108ed447e3d5a7b3581111dff42e3d47dba7829a2964898954c8edc1957f
ep_bytes: 9090b8001040009090906a049090905f
timestamp: 2031-10-15 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43832
MicroWorld-eScanGenPack:Backdoor.Hangup.B
FireEyeGeneric.mg.1b2e504b961bfb47
CAT-QuickHealBackdoor.Berbew
SkyhighBehavesLike.Win32.Generic.kh
McAfeeGenericRXVP-YB!1B2E504B961B
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Backdoor.Hangup.B
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.2EB7E01921
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyTrojan-Spy.Win32.Qukart.af
NANO-AntivirusTrojan.Win32.Qukart.jwfxkp
ViRobotTrojan.Win.Z.Qukart.64512.QDW
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
VIPREGenPack:Backdoor.Hangup.B
TrendMicroTROJ_GEN.R03BC0DJV23
Trapminemalicious.high.ml.score
EmsisoftGenPack:Backdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
MAXmalware (ai score=84)
JiangminTrojanSpy.Qukart.ajay
GoogleDetected
AviraTR/Spy.Qukart.NB
VaristW32/Qukart.K.gen!Eldorado
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.FNZL9N
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacGenPack:Backdoor.Hangup.B
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJV23
TencentTrojan-Ransom.Win32.Pornoasset.a
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b86405
AvastWin32:TrojanX-gen [Trj]

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment