Trojan

What is “TrojanDownloader:Win32/Berbew!pz”?

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 239CA8DFC284B61BBDC4.mlw
path: /opt/CAPEv2/storage/binaries/45a5e64c4a2972b5ecee53cda0e2016bbeb4f80df428013dd5db41b0224b9696
crc32: 5D1FE60E
md5: 239ca8dfc284b61bbdc45b2d50fb24bf
sha1: 4452f1dbb4b68500f59bfa9a2ac9a8a6f6ecf2fb
sha256: 45a5e64c4a2972b5ecee53cda0e2016bbeb4f80df428013dd5db41b0224b9696
sha512: 3f0080bd35ab19a3d9f4afba6629a6b0ac3b57f1bfbe6c6af0b1f13ccb026923050de5f1b0b7916cd3f6e5dda0b0d2093090a6ac9c60b932f86a2f2c93aff4fe
ssdeep: 1536:KX1408O2YPx2NZMo3952ZsJifTduD4oTxw:C140jNP8NJaZsJibdMTxw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166636C4FBA8E0A72D38707F11D7A5FA5B9BD416213ED942064FEC0AD1E03ADCD27A941
sha3_384: 7493b3066521567c531b72cd4eb37640c7cb553979f714955534f7c8e19d3cc1f44b11e295309fec095f09257d32624b
ep_bytes: 90909090609090b800104000bbf87e40
timestamp: 2022-03-16 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.l!c
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43832
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-29
FireEyeGeneric.mg.239ca8dfc284b61b
SkyhighBehavesLike.Win32.Generic.kh
McAfeeTrojan-FVOJ!239CA8DFC284
Cylanceunsafe
ZillyaTrojan.QukartGen.Win32.2
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Qukart.0ebe1042
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.CC3D5BBB21
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.itludo
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftBackdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
VIPREBackdoor.Hangup.B
TrendMicroTROJ_GEN.R002C0DAH24
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
GDataBackdoor.Hangup.B
JiangminTrojanSpy.Qukart.ahbk
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacBackdoor.Hangup.B
MAXmalware (ai score=81)
VBA32BScope.Backdoor.Berbew
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAH24
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.bb4b68
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment