Backdoor

What is “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 0D7B30AB6906D07B2D10.mlw
path: /opt/CAPEv2/storage/binaries/d5058c8ac72ff7cf80b0228b7ecc4cbd4b89fd18d1c6d4eab0fd1a87117ce155
crc32: 3C9D5309
md5: 0d7b30ab6906d07b2d10c7631cd5f4d2
sha1: 38f5a42c463b9e36844f710a5bb92324a676acba
sha256: d5058c8ac72ff7cf80b0228b7ecc4cbd4b89fd18d1c6d4eab0fd1a87117ce155
sha512: 326d97e89afe0fdda0747e2c5a15ab3108a0995168363229b790ae2dd63190a9d6caa76ee8dddbed3a176725fb70e2c2b712bdb379fd66eb8b5c8a5fac8d642a
ssdeep: 1536:TalfLXq3XoHBaMLm4oicU7GDKHnP1SuNCyVso:+zqEB7a43cUyD6ndSdeso
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7435CCB628B0971CB93C2F60B9AD5D2AE2F517CA365F850CCC590283129EEC57BD58D
sha3_384: cf9ccfcf0bdfbcfbcdadd2b9fe6898cf889089f2be618f2218c0bdde31b6fabbab480af8ef6bb5f1cd55e9cd4d79cf77
ep_bytes: 60909090909067e80000000090909090
timestamp: 2023-07-29 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGenPack:Backdoor.Hangup.B
FireEyeGeneric.mg.0d7b30ab6906d07b
SkyhighBehavesLike.Win32.Generic.qh
ALYacGenPack:Backdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Backdoor.Hangup.B
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
ClamAVWin.Trojan.Crypted-36
KasperskyTrojan-Spy.Win32.Qukart.af
NANO-AntivirusTrojan.Win32.Qukart.iqdkfm
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREGenPack:Backdoor.Hangup.B
Trapminemalicious.high.ml.score
EmsisoftGenPack:Backdoor.Hangup.B (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
JiangminBackdoor.Padodor.noh
GoogleDetected
AviraTR/Spy.Qukart.NB
VaristW32/Qukart.K.gen!Eldorado
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataGenPack:Backdoor.Hangup.B
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOK!0D7B30AB6906
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-Ransom.Win32.Pornoasset.a
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.6CDB3E0D1E
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c463b9
AvastWin32:TrojanX-gen [Trj]

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment