Backdoor

About “Backdoor:Win32/Berbew!pz” infection

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: D51161E309A7B20CAF29.mlw
path: /opt/CAPEv2/storage/binaries/46ef91cc197cb58fc843229a6949d08f463642e46d2671ca7e9f6d7ed45ef734
crc32: 34C78507
md5: d51161e309a7b20caf29d620aad64d4e
sha1: 96edc9b1bd4e5dedfc4def66fc2191aa50c0762c
sha256: 46ef91cc197cb58fc843229a6949d08f463642e46d2671ca7e9f6d7ed45ef734
sha512: a8cb2b196b75a181cfdd309649409d2859ac61c46871871aafcacca215c9aaed041a0cecccc2139e6a11b08bc0ddcdf4f8b5dc97e0ed3f0f13156b5831f03aed
ssdeep: 3072:gdolN+eJDfjP5hHJYIuYUvIMDrFDHZtOgxBOXXwwfBoD6N3h8N5G2qVUDrFDHZth:6cN+exfjP5j44s5tTDUZNSN58VU5tTtf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129246A5B5E5B2251CD4FC0757C4F21B195E887EBAF9835508CEB8018B72DAC842BB9B3
sha3_384: 580ac76ac58ca280eb1e4b6affe345819ae2ffbe4d3a99fa35d5a6454c76b01c17e7a5c70de43089cf9aaf9e51467153
ep_bytes: 906090909090b8001040009090bbf87e
timestamp: 2018-02-05 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43832
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-30
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Backdoor.dc
McAfeeTrojan-FVOJ!D51161E309A7
MalwarebytesGeneric.Malware.AI.DDS
VIPREBackdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.05368a07
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitBackdoor.Hangup.B
BitDefenderThetaAI:Packer.493E2EB61E
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.iuehka
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
EmsisoftBackdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
ZillyaTrojan.QukartGen.Win32.1
TrendMicroTROJ_GEN.R002C0DLE23
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Qukart.ajlg
GoogleDetected
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=81)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
KingsoftWin32.Troj.Undef.a
MicrosoftBackdoor:Win32/Berbew!pz
ViRobotTrojan.Win.Z.Qukart.229376.ADVC
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.1A8ERTK
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLE23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojanSpy.Qukart!ilrg4T3MCO4
IkarusTrojan.Spy.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.1bd4e5
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment