Trojan

TrojanDownloader:Win32/Berbew!pz information

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 4E734A4375C5E5FB1B38.mlw
path: /opt/CAPEv2/storage/binaries/cd07f3f8741cb5a535871b5e4e8ef81d98384314bf7efc103c20f00318e7e5af
crc32: 68F7CF76
md5: 4e734a4375c5e5fb1b3829335e50bf86
sha1: ef158e71b02adca83721c85c35b2c9fd87b46c63
sha256: cd07f3f8741cb5a535871b5e4e8ef81d98384314bf7efc103c20f00318e7e5af
sha512: 37ad974d382d5dabea45bcd0cb57101181b1884fbab18c08529baf5b4382829f62bee3aab97be866a7b0fc7b29c2f46daf331f1173f789563d2ab674233ba82e
ssdeep: 3072:ajn5gM1WfsPgoO8OyyxE1cjENRZ9wmAOIayGsOOJF4EISi/i4gG4npAjmA39QQIw:aD1WfsPIhE1nTZ9EaUn4yjK99QQd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC044C7BE1CA1F72C34FC2F516466DDEA7258039139DC550F458801F277AA6C92BEE90
sha3_384: d8077a891c7fc91d4c493e6a3e0f708415ba200855cc283b3be349f86e2c7f310b5dc744c0288cd444d68d2f263f385b
ep_bytes: 60909090909090b8001040009090906a
timestamp: 2024-12-10 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Backdoor.Hangup.B
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.ch
McAfeeTrojan-FVOJ!4E734A4375C5
Cylanceunsafe
ZillyaTrojan.Qukart.Win32.3410036
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.3d6d29e9
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.1b02ad
ArcabitGenPack:Backdoor.Hangup.B
BitDefenderThetaAI:Packer.5621D6C421
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.ixmkis
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
EmsisoftGenPack:Backdoor.Hangup.B (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREGenPack:Backdoor.Hangup.B
TrendMicroTROJ_GEN.R03BC0DLL23
SophosMal/Padodor-A
IkarusTrojan.Spy.Qukart
JiangminTrojanSpy.Qukart.ajqe
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ViRobotTrojan.Win.Z.Qukart.180389.FWL
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataWin32.Trojan.PSE.1A8ERTK
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGenPack:Backdoor.Hangup.B
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLL23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojan.GenAsa!FrLL7FUDrD4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment