Backdoor

What is “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: E6041127645C574AC498.mlw
path: /opt/CAPEv2/storage/binaries/0ceab9316d1862033f1656f428c62d57c3756111ba8682cedb2d4e1a76dced3f
crc32: 2CEE999B
md5: e6041127645c574ac498182a53726c5f
sha1: 7b6022a744331b3c0b7c257782a5b6e5d8ad370e
sha256: 0ceab9316d1862033f1656f428c62d57c3756111ba8682cedb2d4e1a76dced3f
sha512: 8106c2c6960bef11dbeabf97d01d37d230c99ff7be0d00c63f668c2e1f58cd8945433829d574d66ae6711d5702e01821e451940a4987b56be482bd4669fb53a1
ssdeep: 768:Jj+jKcdCVqz1fgRiVs9eT5mETIdSfwflQV0NiqfEnhK+mHoZ/1H53YR5nf1fZMEd:JjxHs1fgRi64XISPqMK+mHKCNCyVso
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124436CC7934B2F5FF2DF01751707D5E2AD39E93A03658187085961A93B073888DEEA8D
sha3_384: 911c63a494ac04936a01e86806763d69a86b1c130d55c3a77b6a0c46e32d3a51706df489f87de60dbd0131cfcd2cced3
ep_bytes: 909060909090b8001040009090bbf87e
timestamp: 2023-07-29 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.4!c
MicroWorld-eScanBackdoor.Hangup.B
FireEyeGeneric.mg.e6041127645c574a
SkyhighBehavesLike.Win32.Generic.qh
McAfeeTrojan-FVOJ!E6041127645C
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Qukart.Win32.2424770
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.f4e3a6e1
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.744331
BitDefenderThetaAI:Packer.6CDB3E0D1E
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jvjtpy
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftBackdoor.Hangup.B (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREBackdoor.Hangup.B
TrendMicroTROJ_GEN.R002C0DHL23
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminTrojanSpy.Qukart.iv
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataBackdoor.Hangup.B
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacBackdoor.Hangup.B
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DHL23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment