Backdoor

Backdoor:Win32/Berbew!pz malicious file

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 340FDB6D40FEBBEDA923.mlw
path: /opt/CAPEv2/storage/binaries/26bb0152f463ef0e562356d52328a6d661aa414d2a4f2427a94a6d129992d6d5
crc32: 9E8B3301
md5: 340fdb6d40febbeda92371be6849cddf
sha1: 67786b9f2c2e6f0fb71ccfabbbe61264b698527e
sha256: 26bb0152f463ef0e562356d52328a6d661aa414d2a4f2427a94a6d129992d6d5
sha512: 5f554efc9551b50d24a5690c896f08727c0c3cad0bdda923a218906e0f0de642061c4b83d438539de65a757be44baddc55aa1f4ab05f2fb14f99bd7a24daf229
ssdeep: 3072:UoIH+oS69XGAIuYUvIMDrFDHZtOgxBOXXwwfBoD6N3h8N5G2qVUDrFDHZtOgtSU:UoIet0Gg4s5tTDUZNSN58VU5tTtf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA246B7B5E5B1271C163C1B75C4321A196EBC7E72F9836649CEBC02D932DA0883B598F
sha3_384: 5a238459eb67474edc69de117d4572f78fbb34e8a64dcab46ad3408898ebe3a7601e3cc91979b65b7597f30f5004ec0c
ep_bytes: 90909090609067e80000000058909090
timestamp: 2018-02-05 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43832
MicroWorld-eScanGenPack:Backdoor.Hangup.B
ClamAVWin.Trojan.Crypted-29
CAT-QuickHealWorm.Dorkbot.A
McAfeeTrojan-FVOK!340FDB6D40FE
Cylanceunsafe
ZillyaTrojan.QukartGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.98ad2173
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.f2c2e6
ArcabitGenPack:Backdoor.Hangup.B
BitDefenderThetaAI:Packer.493E2EB61E
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.iwphpd
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
SophosMal/Padodor-A
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
VIPREGenPack:Backdoor.Hangup.B
TrendMicroTROJ_GEN.R03BC0DL823
EmsisoftGenPack:Backdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
JiangminTrojan.Generic.gzrms
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ViRobotTrojan.Win.Z.Qukart.229376.ABVV
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.1A8ERTK
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
TACHYONBackdoor/W32.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DL823
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojanSpy.Qukart!ilrg4T3MCO4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment