Trojan

What is “TrojanDownloader:Win32/Berbew!pz”?

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 572AACB5D1558F8050DA.mlw
path: /opt/CAPEv2/storage/binaries/2a3d36c32ba485554aac73312b6f3ee91259cf9f0c7e85d9521ce5869c46d4ba
crc32: A41573CB
md5: 572aacb5d1558f8050da6865a18c659c
sha1: 78a70d24ab469192e8e067b8dd23a9919a34c510
sha256: 2a3d36c32ba485554aac73312b6f3ee91259cf9f0c7e85d9521ce5869c46d4ba
sha512: 9426af6e3c884bddbb146725990a9305e98784c5585f5a60e6c9ca5f028df7fc9a4a08f5a8eda752a90fb73623d429c501d043472d507226a5a42139b852f4a7
ssdeep: 1536:+0is3kN7A/TTlPAQjILQ9FKGXllUDtM60TD4ruhiZlrQIFiglF9xZ95Q:liNFALpPHKG7UDd0pCrQIFdFtLQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159D3195BB38B0372C1D302B12A4F59D6F72A907963B785D35CD8806D12E6EFC827A395
sha3_384: 732e3226e07cbc9456aa572ad2954ccf10c19b96084a03daab531efa679f4d8e3cf42dd45102cb6ae07ef8c0df55023b
ep_bytes: 909060909090b8001040009090bbf87e
timestamp: 2031-10-15 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Hangup.B
SkyhighBehavesLike.Win32.Generic.cm
McAfeeTrojan-FVOJ!572AACB5D155
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.4ab469
BitDefenderThetaAI:Packer.3E5D7A3421
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftBackdoor.Hangup.B (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREBackdoor.Hangup.B
FireEyeGeneric.mg.572aacb5d1558f80
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15MS2TX
JiangminTrojanSpy.Qukart.ahax
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Spy.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment