Backdoor

Should I remove “Backdoor.Berbew”?

Malware Removal

The Backdoor.Berbew is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Berbew virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Berbew?


File Info:

name: A8DB55054E8CFA67E9BB.mlw
path: /opt/CAPEv2/storage/binaries/431001dc7e37a3ea324d652f884a8a15feba1115058aac81f99660dc6105a595
crc32: 582B4727
md5: a8db55054e8cfa67e9bb4d263e52ff4e
sha1: 11ebadb67f8abef26d6acd2ea3bfd24f5e0621c5
sha256: 431001dc7e37a3ea324d652f884a8a15feba1115058aac81f99660dc6105a595
sha512: 15a355395c29f702a827160f56ea42dbff453fcb4c707b93364b36ff0aa80105308f332dcefcb532b1c3047c8a9e9178c7be4939bf76a925b9f7049db8034c10
ssdeep: 12288:lHp8vSXJJO/awrSmfyiPFg8prNdw+C7797TnPtLU8deJUP//zk9FGB:lH8wJO/awrSmfyiPFg8prNdw+C7797T3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167941B2FB7451772C28103B23A0F98D6B72E967A237A85A05478C41D3367E3893BB7D5
sha3_384: e3aeb218d20c9e1e8280883f959590d1c4675da4a300d483f3ad60cbc6c48a1976d549cc8a281910fc067e1e8f75127c
ep_bytes: 609090909090b80010400090bb38de40
timestamp: 1982-02-08 05:39:38

Version Info:

0: [No Data]

Backdoor.Berbew also known as:

tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98109
ClamAVWin.Trojan.Crypted-28
CAT-QuickHealBackdoor.Berbew
McAfeeGenericRXPE-AP!51E8B0F3C43C
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.Padodor.Win32.549727
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.54e8cf
CyrenW32/Backdoor.DKIC-2994
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.98109
NANO-AntivirusTrojan.Win32.Padodor.jvnqte
AvastWin32:Padodor-V [Trj]
TencentTrojan.Win32.Qukart.ya
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.GenericKDZ.98109 (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.98109
TrendMicroTROJ_GEN.R03BC0DDT23
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a8db55054e8cfa67
SophosTroj/Padodo-Gen
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.28UEQN
JiangminBackdoor.Padodor.erlj
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitTrojan.Generic.D17F3D
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Berbew.AA!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
BitDefenderThetaAI:Packer.DF982C4621
ALYacTrojan.GenericKDZ.98109
MAXmalware (ai score=89)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DDT23
RisingRansom.PornoAsset!8.6AA (TFE:2:dQq3nsYFyrD)
IkarusBackdoor.Win32.Padodor
FortinetW32/Krato.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Berbew?

Backdoor.Berbew removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment