Trojan

TrojanDownloader:Win32/Berbew!pz malicious file

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary compilation timestomping detected
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: B6E43776BD9180D4441D.mlw
path: /opt/CAPEv2/storage/binaries/2fb2e21de5317afc5ce21b7273b8f4dd4bfb4e17628afa78aa558de775507bf5
crc32: CC82DB10
md5: b6e43776bd9180d4441d6610664f9e2e
sha1: 5c678ebdc985eb0ebf8ffbc741a0419bcb9172fb
sha256: 2fb2e21de5317afc5ce21b7273b8f4dd4bfb4e17628afa78aa558de775507bf5
sha512: 16409d68b166764f9a60dfd532a0b37c641689882338bc34d4b64399a7dc69c623a4ab2882935880f21dfaf002e00014dff949a88e878109bd01cb4b2d384cc0
ssdeep: 3072:7cqIN0IEOZM1ULXE84DWufKG7UDd0pCrQIFdFtLQ:YqIN0IEMSC43iG7Ux0ocIPF9Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DD33B7B76851772C1BF3F72210A6AF2B32D913B236655FF3858811D3652BE846B7280
sha3_384: 47d2982dd579ee81cd7f59d2a27c3dfd249ad84d32496649a43cc98613b2db96eda6b08174d67dc7d6ecda0ff5270c11
ep_bytes: 609090909090b80010400090906a0490
timestamp: 2031-10-15 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Backdoor.Hangup.B
ClamAVWin.Trojan.Crypted-28
FireEyeGeneric.mg.b6e43776bd9180d4
SkyhighBehavesLike.Win32.Generic.cm
McAfeeTrojan-FVOJ!B6E43776BD91
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Backdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.kcdiva
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
ZillyaTrojan.QukartGen.Win32.2
Trapminemalicious.high.ml.score
EmsisoftGenPack:Backdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
GDataWin32.Trojan.PSE.15MS2TX
JiangminTrojanSpy.Qukart.ahel
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.3E5D7A3421
ALYacGenPack:Backdoor.Hangup.B
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.dc985e
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment