Malware

About “Win32:Bertle” infection

Malware Removal

The Win32:Bertle is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Bertle virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Win32:Bertle?


File Info:

name: F916314A322FF38DF7D2.mlw
path: /opt/CAPEv2/storage/binaries/b4675a6fca882c234eb48edb8cad6c0ba5a6083d05ef529013a035bb013f06cb
crc32: B753BC3E
md5: f916314a322ff38df7d23003ecdd981d
sha1: 8c3d3ccc3282868e973b00eff3f2a185bb9a9c80
sha256: b4675a6fca882c234eb48edb8cad6c0ba5a6083d05ef529013a035bb013f06cb
sha512: 55fb9936695e75a50b44fb5b8ddb51f7328234af5e9e1f6bffe9b372f0f5469a822ada6e1a266a974e81a78c6f04778b79306b37d5b6fcbec8fc9eda468cb492
ssdeep: 6144:N+K6FIohAGjUVpFzWpkChCV+1mEBoPP5mI83j5brh9tkjCHFq9N:N+KuIMq0kCwV+11mng3j5brh9tkjCHFm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11574E13EA536E024DF9A20BE0452B955AF44893C6EF151409D8FE0E3B77E597F08C6E4
sha3_384: ee9905b669515d0d4bfe5b157af47017f41d8ddc8922690b1ff7c3c2bc7f6a5ebf0fd31a6695abf9a49a5a222e01fa15
ep_bytes: 6a00e83d080000a3b0314000bf003040
timestamp: 2003-04-03 20:34:32

Version Info:

0: [No Data]

Win32:Bertle also known as:

BkavW32.Bertle.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Bertlea.A
FireEyeGeneric.mg.f916314a322ff38d
ALYacWin32.Bertlea.A
CylanceUnsafe
ZillyaVirus.Bertle.Win32.1
K7AntiVirusVirus ( 0008d74f1 )
K7GWVirus ( 0008d74f1 )
Cybereasonmalicious.a322ff
BaiduWin32.Virus.Bertle.a
CyrenW32/Bertle.NAXZ-5324
SymantecW32.Bertle
ESET-NOD32Win32/Bertle.A
APEXMalicious
ClamAVWin.Worm.Bertel-1
KasperskyVirus.Win32.HLLP.Bertle.4608
BitDefenderWin32.Bertlea.A
NANO-AntivirusVirus.Win32.Bertle.fzbu
AvastWin32:Bertle
RisingWorm.Bartly!1.A172 (CLASSIC)
Ad-AwareWin32.Bertlea.A
SophosML/PE-A + W32/Bertle-A
ComodoVirus.Win32.Bertle.AA@4zfm5u
DrWebWin32.HLLP.Bert.4608
VIPREBehavesLike.Win32.Malware.vfm (mx-v)
TrendMicroPE_BERTLE.A
McAfee-GW-EditionW32/HLLP.4608
EmsisoftWin32.Bertlea.A (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Bertlea.A
AviraW32/HLLP.Bertl.4608
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASVirus.17B
ArcabitWin32.Bertlea.A
MicrosoftWorm:Win32/Bartly.A
CynetMalicious (score: 100)
AhnLab-V3Win32/HLLP.C
Acronissuspicious
McAfeeW32/HLLP.4608
MAXmalware (ai score=88)
VBA32Virus.Hubert.21207
MalwarebytesMalware.AI.1725748148
TrendMicro-HouseCallPE_BERTLE.A
TencentTrojan.Win32.BitCoinMiner.la
YandexWin32.Bertle.4608
IkarusVirus.Win32
MaxSecureVirus.W32.HLLP.Bertle.4608
FortinetW32/Bertle.4608
BitDefenderThetaAI:FileInfector.39D7DB360F
AVGWin32:Bertle
PandaW32/Bertle.4608
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32:Bertle?

Win32:Bertle removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment