Trojan

TrojanDownloader:Win32/Berbew!pz removal guide

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 7B016DB7E3A7C0260908.mlw
path: /opt/CAPEv2/storage/binaries/56037dcfbe2c618255af9a400ae71e7d36deed85330b19ea88c29c12c51649c7
crc32: 89EE1E45
md5: 7b016db7e3a7c0260908e5e57acf27df
sha1: 3276abada32485653729a5ebc0388d50cdcf2668
sha256: 56037dcfbe2c618255af9a400ae71e7d36deed85330b19ea88c29c12c51649c7
sha512: 30344dc45e5d4a8de1baa7d4956c601bec6b2116101158e47dca6f1f7f9b17149944d579ec00c65b4e9fada628066107fea4f68e55af321f399ff7ca8c3232c2
ssdeep: 6144:FW/rtMgMMaB4muz14QaYgTt+scaHACw6Ykw/a8dWBtp27DpomqcPMwNFN6aeK9kc:FWTtu1uznghoaHACwBkka8eGp7dPRr6G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17774F96FB38513B2C28203F2761F59D6B72D957923BA95E02468C01D13A7F2C93BB6D4
sha3_384: 4b75aad61f8130bfc7f4b2ea1ee8d7f07501f0a8cc7f41b1bc791f2c56df9fa6c6dd3af26b0d8e3406060f4dfe6bc811
ep_bytes: 909060909090b800104000906a049090
timestamp: 2013-12-28 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Backdoor.Hangup.B
FireEyeGeneric.mg.7b016db7e3a7c026
CAT-QuickHealBackdoor.Berbew.S31353865
SkyhighBehavesLike.Win32.Generic.fm
McAfeeTrojan-FVOJ!7B016DB7E3A7
Cylanceunsafe
VIPREGenPack:Backdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.835546c3
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.da3248
BitDefenderThetaAI:Packer.D492E28B21
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.kckciv
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
ZillyaTrojan.QukartGen.Win32.2
Trapminemalicious.high.ml.score
EmsisoftGenPack:Backdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
GDataWin32.Trojan.PSE.1A8ERTK
JiangminTrojanSpy.Qukart.ahbz
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
KingsoftWin32.Troj.Undef.a
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacGenPack:Backdoor.Hangup.B
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Qukart.A!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment