Trojan

TrojanDownloader:Win32/Berbew!pz removal instruction

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 5B530B4E4A39DC573C98.mlw
path: /opt/CAPEv2/storage/binaries/e2c2e12b28efd3fcbb1b0be51f0ff99e933413a460efb936167811403c58a563
crc32: D0C38F9C
md5: 5b530b4e4a39dc573c98d384faed3a80
sha1: e3d8a7286103faf9cc29401b9a8c692180fab0ea
sha256: e2c2e12b28efd3fcbb1b0be51f0ff99e933413a460efb936167811403c58a563
sha512: 378e142e21923c5cfbacdbdaab740c0c6f50c7ec6be8c51d0c5c81ff712494f91c98bc7ea6d63b40cf56b86c253133500dacae9db7e003efc0cf9cf250790116
ssdeep: 1536:1Xe3yWf1HfOeEEXyXX888gxBD+VCEn9rjDHE:1Xe3yWfF3EEXyXX888gxBDoCk9DHE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E536B4F63851AE6DCC30171248636AAFA35526413FB478158BFC0EE1FCB6EC11B5A9D
sha3_384: 434a95567f22e44e4210e2c879ae51b67850f13a58dfc8ec71ebbf5ed409f359ac5132487476c37f9943ca408666c963
ep_bytes: 906090b80010400090bbf87e4000b92d
timestamp: 2031-10-15 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Hangup.B
SkyhighBehavesLike.Win32.Generic.kh
McAfeeTrojan-FVOJ!5B530B4E4A39
MalwarebytesGeneric.Malware.AI.DDS
VIPREBackdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.fcd264a9
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.86103f
ArcabitBackdoor.Hangup.B
BitDefenderThetaAI:Packer.2EB7E01921
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jwvecu
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Spy.Win32.Qukart.ka
TACHYONBackdoor/W32.Padodor
EmsisoftBackdoor.Hangup.B (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
ZillyaTrojan.Qukart.Win32.3194730
TrendMicroTROJ_GEN.R002C0DL823
SophosMal/Generic-S
IkarusTrojan.Spy.Qukart
JiangminTrojanSpy.Qukart.ajao
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ViRobotTrojan.Win.Z.Qukart.64512.VQD
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.5ABJGG
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DL823
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment