Trojan

About “TrojanDownloader:Win32/Berbew!pz” infection

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary compilation timestomping detected
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: A611A3712F648D4E7E36.mlw
path: /opt/CAPEv2/storage/binaries/15feb10748e07dc403a6bf2125d6c47d8f85d4d732b21c76a705d849a8d08db7
crc32: 0512DDBC
md5: a611a3712f648d4e7e36810c9e58144c
sha1: 2da8839a09cb237ae4ba9272f8d57839ff419e9f
sha256: 15feb10748e07dc403a6bf2125d6c47d8f85d4d732b21c76a705d849a8d08db7
sha512: 2739eabd896f3060c9d3e67e3fb5033df2966a021f79f696ac199f77cdf1bfbefea633a1f9f94efe7f2f86e4bf735bfb7c30a81045dffde22d9acff868e9f4d3
ssdeep: 3072:Pko4pzV6ntbil1cjENRZ9wmAOIayGsOOJF4EISi/i4gG4npAjmA39QQIckJI:HuV6nhil1nTZ9EaUn4yjK99QQd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C044B7BA14A07A1C752CEF5165E79DEA325C0F913978550F01CB01F1F32AD886BAEB4
sha3_384: be78d597d00461e37c8869a0c651812e12300d8744971d13d113f7d4f15c167eb1699fa388880dd6b050175173f884cc
ep_bytes: 909090906090b80010400090bbf87e40
timestamp: 2024-12-10 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-29
FireEyeGeneric.mg.a611a3712f648d4e
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.ch
McAfeeTrojan-FVOJ!A611A3712F64
MalwarebytesGeneric.Malware.AI.DDS
VIPREBackdoor.Hangup.B
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.iqziyu
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftBackdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
ZillyaTrojan.QukartGen.Win32.2
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Spy.Qukart
GDataWin32.Trojan.PSE.1A8ERTK
JiangminTrojanSpy.Qukart.ajps
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacBackdoor.Hangup.B
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojan.GenAsa!FrLL7FUDrD4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.5621D6C421
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.a09cb2
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment