Backdoor

Should I remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: A39552AF9F4688E5D22A.mlw
path: /opt/CAPEv2/storage/binaries/8faad1918b90a8ee352ac98a72cb61627c060f267c5bc6e37fecfb81eb4ca7b9
crc32: 6349A136
md5: a39552af9f4688e5d22ab7c369e1327b
sha1: f72ceed056ba842793468c54785d5c4edb77a945
sha256: 8faad1918b90a8ee352ac98a72cb61627c060f267c5bc6e37fecfb81eb4ca7b9
sha512: b758e1001ed4e4eae51da6d05ee6911505ef6eba06f6772394920a6ad510a88ddaef8b63a3ee7f2130e81b8d15738c6bfb7c8023e335df6be7f15692032e81f4
ssdeep: 6144:hksghEKeYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qve6UK+42GTQMJSZE:hbKeYr75lTefkY660fIaDZkY660f2lTS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B848B0BB9AF8E21C653007E900E8F567EE6612CD1EAC0511CE5E54EE603DC55BBB9B3
sha3_384: 8c851bfe94740e9d9a8ace80153a5b58903be5a1f80b3d1940e5c18fb606548de4197f78fd001bed05740df8c1154ef2
ep_bytes: b8001040009090bb38de4000b93c0159
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
DrWebBackDoor.Wdozer
MicroWorld-eScanTrojan.GenericKDZ.102778
FireEyeGeneric.mg.a39552af9f4688e5
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeGenericRXPE-AP!E25F2B635978
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.102778
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderTrojan.GenericKDZ.102778
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.056ba8
BitDefenderThetaAI:Packer.62E4432421
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Lazy-10001745-0
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.iutoew
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
TACHYONBackdoor/W32.Padodor
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XDR.Gen
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.102778 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.evwa
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitTrojan.Generic.D1917A
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kl
YandexTrojan.GenAsa!p1fO5hhCx5A
IkarusTrojan.Win32.Padodor
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment