Backdoor

Backdoor.Berbew.S30943575 information

Malware Removal

The Backdoor.Berbew.S30943575 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Berbew.S30943575 virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Berbew.S30943575?


File Info:

name: C5E60D991F871C665E81.mlw
path: /opt/CAPEv2/storage/binaries/6dd64b867def84c3b9f47755453d58816b39d5edf381ee8e1adedfc5d2549498
crc32: D07442AA
md5: c5e60d991f871c665e810ebb415f3d13
sha1: 28ecf4868f367db3570ef5e14955def345048c6c
sha256: 6dd64b867def84c3b9f47755453d58816b39d5edf381ee8e1adedfc5d2549498
sha512: 254dbfd988af3a6de4bcc34c7e1a0a13fb969a0beee8aaf3c107533565325ca7de40f05d8997aeb6e6b9bd08e5eeff18d60a9c7a3751317f1d8c7cd504523e22
ssdeep: 1536:dbiaA0Txanh/LWGH1azYKmJ4aPQRQ+CPR5R45WtqV9R2R462izMg3R7ih9:1iaA0TKh/LpaTkoe+CPHrtG9MW3+3l29
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EA37BABBB4A1FA3DD2203BC631E4DFAFB15A175366DB4D22469802C1142E5C8F7F254
sha3_384: 77f35917457269ea1bba155a4d14bdd63c07e7a23dbfdf46c8949445bda390e1c8bb6898318483f6b32fd9099895d334
ep_bytes: 90909090906090b80010400090bbd0c7
timestamp: 2012-04-24 03:39:59

Version Info:

0: [No Data]

Backdoor.Berbew.S30943575 also known as:

tehtrisGeneric.Malware
DrWebBackDoor.HangUp.5
MicroWorld-eScanTrojan.Agent.DQQO
CAT-QuickHealBackdoor.Berbew.S30943575
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!C5E60D991F87
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1013400
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.68f367
BitDefenderThetaAI:Packer.617771141E
SymantecBackdoor.Berbew
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.fmppyt
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Qukart.ya
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPRETrojan.Agent.DQQO
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c5e60d991f871c66
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
GDataTrojan.Agent.DQQO
JiangminBackdoor.Padodor.erky
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Berbew.AA!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.Agent.DQQO
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Berbew.S30943575?

Backdoor.Berbew.S30943575 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment