Backdoor

Should I remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 8FD8C96D9A5608A87DF3.mlw
path: /opt/CAPEv2/storage/binaries/39a31ce9f4df72dac4f5fd907dcb21393bc9637a5b2a189f1f284af75aff4245
crc32: 95268389
md5: 8fd8c96d9a5608a87df3e3517c711e39
sha1: e3e15578c490ae2ecf0b9423b3e8439f3f12131b
sha256: 39a31ce9f4df72dac4f5fd907dcb21393bc9637a5b2a189f1f284af75aff4245
sha512: 2e7bc76c7139e1c878d7b675eb2aa87e60a0d8114627246930735bdc6109464ecd1c6a9dd39f3bc8577229bc56350e27cd9f405e9b567972c96ee218fcb3fc48
ssdeep: 3072:tgc1MiLwvkKVnZn1TdzUAEQGBcHN0OlaxP3DZyN/+oeRpxPdZFibDyxn:fekwvkKVnZ1Z4AHj05xP3DZyN1eRppz1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155E34A6FB64417B2C5D322B2234ED8E6BB3D807B136985A0F078C01DA757E2852FB795
sha3_384: 2756022c000ab267b4034ce9a137dc624724b4f50843c3bc3ebd00f28324c0f5a1dae9efb6b345975c640a33b514e08e
ep_bytes: 909090909060b8001040009090bbd08e
timestamp: 1972-09-27 00:00:00

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.1.Backdoor.Hangup.A.36FDD0E9
ClamAVWin.Trojan.Crypted-31
FireEyeGeneric.mg.8fd8c96d9a5608a8
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.cm
ALYacGeneric.Dacic.1.Backdoor.Hangup.A.36FDD0E9
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.8c490a
ArcabitGeneric.Dacic.1.Backdoor.Hangup.A.36FDD0E9
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
SymantecBackdoor.Berbew.F
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderGeneric.Dacic.1.Backdoor.Hangup.A.36FDD0E9
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen13.42746
VIPREGeneric.Dacic.1.Backdoor.Hangup.A.36FDD0E9
TrendMicroTROJ_GEN.R03BC0CKG23
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.1.Backdoor.Hangup.A.36FDD0E9 (B)
IkarusTrojan-Spy.Win32.Qukart
JiangminTrojan.Generic.dzrgt
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GDataWin32.Trojan.PSE.6Y1WGK
VaristW32/S-7ac9acda!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!8FD8C96D9A56
MAXmalware (ai score=83)
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CKG23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.A3320B7E21
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment