Trojan

About “TrojanDownloader:Win32/Berbew!pz” infection

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: AB0EB4611A772C0EFF66.mlw
path: /opt/CAPEv2/storage/binaries/8ef627d1dab2c114eb51868538a08e8aa70379d117caea3a96fedc22179eac33
crc32: 6AEB012A
md5: ab0eb4611a772c0eff66a0c6d71cbc8a
sha1: 0e8c5b0fdad90a6e2d9ce49cec24fdbc56d465a7
sha256: 8ef627d1dab2c114eb51868538a08e8aa70379d117caea3a96fedc22179eac33
sha512: 29be528e92a2ba305888ec18ac00f2b2f9823fdabc803e83107e4e9841fb34ae14d0b4b32f0dfb85c75d23459b0608485cae01cd502dc9662d52584de072ed64
ssdeep: 1536:PIkBugZj+DaHVkpXf0zRMK0UhaHDlbnGx+aNCyVso:PHB8yApVheso
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187438EC776EA291DC99702F4075787F6B131606F13AA74A02934C36A362929F2F77E03
sha3_384: 79fce3f0d554aa4de6a38494c7bdfec8fa4a7ea4e4499bf2362e3add53da307796d6f1d10f682e00f69cf212d1bf2458
ep_bytes: 60909067e80000000058909090909005
timestamp: 2023-07-29 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Backdoor.Hangup.B
ClamAVWin.Trojan.Obfus-38
SkyhighBehavesLike.Win32.Generic.qh
McAfeeTrojan-FVOK!AB0EB4611A77
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.aed9eb45
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.fdad90
ArcabitGenPack:Backdoor.Hangup.B
BitDefenderThetaAI:Packer.806D3CE11D
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.ivupjb
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftGenPack:Backdoor.Hangup.B (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREGenPack:Backdoor.Hangup.B
TrendMicroTROJ_GEN.R002C0DA624
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminTrojanSpy.Qukart.ajbr
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataGenPack:Backdoor.Hangup.B
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DA624
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment