Trojan

What is “TrojanDownloader:Win32/Berbew!pz”?

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 0EA1319A1088E749FA88.mlw
path: /opt/CAPEv2/storage/binaries/ce43232a3879d388bd04a7872f8e756e6e27d714be31582abda141261db25332
crc32: 934BA5E6
md5: 0ea1319a1088e749fa883a7006b0529c
sha1: e842070d7180dd74e34208d0baf15af42a5744ec
sha256: ce43232a3879d388bd04a7872f8e756e6e27d714be31582abda141261db25332
sha512: e7be4aa2187a81b77145de4bb24010fac7a8affafe43890883e4841243e0b72a52d0c40bcbb143d76a9f849ba3cf26693f1e6ee7042d2cb3fae7e5bd3872606a
ssdeep: 1536:8gZASb3I53GHyokAJ89uUfipz8sJifTduD4oTxw:USc3GHyo1J8kYipz8sJibdMTxw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191638CABB2A61A22C05323736557A4F6A63CB877D76F4744C814814C0736EF88E7B7C6
sha3_384: e573cbbe35978c65d5722633695df233033fe684cb7ec0cad1cefb17191228adeb1751799565abde0eb54ece26049e87
ep_bytes: 609090909090b80010400090bbf87e40
timestamp: 2022-03-16 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43832
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-28
SkyhighBehavesLike.Win32.Generic.kh
McAfeeTrojan-FVOJ!0EA1319A1088
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.QukartGen.Win32.2
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.d7180d
BitDefenderThetaAI:Packer.CC3D5BBB21
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jwjxnx
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftBackdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
VIPREBackdoor.Hangup.B
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0ea1319a1088e749
SophosMal/Padodor-A
IkarusTrojan.Crypt
GDataBackdoor.Hangup.B
JiangminTrojanSpy.Qukart.ahel
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacBackdoor.Hangup.B
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment