Trojan

About “TrojanDownloader:Win32/Berbew!pz” infection

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 05AD28502994A44A6DC7.mlw
path: /opt/CAPEv2/storage/binaries/ee73a74da2aeb677ff3f89dd5e7d051e2b1810153f249e0a33606d15e1ac65a9
crc32: 5B6273EB
md5: 05ad28502994a44a6dc773d1221bc28a
sha1: f69ca6a5c857b74ae40aba21be7df604a8ba49f6
sha256: ee73a74da2aeb677ff3f89dd5e7d051e2b1810153f249e0a33606d15e1ac65a9
sha512: 5111d2ba96730d0e1c8de60fb7e73059931451be0b073017d7a09cfedf9c849178006ac54e1a7a8f2749a459c7b25debef3b3008b8db01252797380877afc236
ssdeep: 768:ql0L82DniKYfGNx3I1V/CtHvZrf6osK7hbDwffZ/1H5xN5nf1fZMEBFELvkVgFR:Q0L82eKugxykBmo3SPnNCyVs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164434BEF498C6F76DCF70772B642C3C3B2375CA543A5BBD26871832862709687D29894
sha3_384: 9ed77de501340d609de2a7af66c6b3cb325dae80d1d0c6f6c197932403cf2cda213690a95d76bb459cd5fcd396c09b1b
ep_bytes: 90909090b800104000bbf87e40009090
timestamp: 2023-07-29 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebBackDoor.HangUp.43832
MicroWorld-eScanGenPack:Backdoor.Hangup.B
SkyhighBehavesLike.Win32.Generic.qh
ALYacGenPack:Backdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Backdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.5c857b
ArcabitGenPack:Backdoor.Hangup.B
BitDefenderThetaAI:Packer.594D2E4D1D
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Renos-10003934-0
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.kbrtld
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftGenPack:Backdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.05ad28502994a44a
SophosML/PE-A
IkarusTrojan.Crypt
JiangminTrojanSpy.Qukart.ajbr
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataGenPack:Backdoor.Hangup.B
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXVP-YB!05AD28502994
MAXmalware (ai score=83)
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment