Backdoor

Backdoor:Win32/Berbew!pz malicious file

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: EE7658D4F85D9D2377CD.mlw
path: /opt/CAPEv2/storage/binaries/b8a6e055f87a6d3e0698f5c7fe3daa99291d6ba7745c9690b87f8260dfe25e5e
crc32: EE1E0D75
md5: ee7658d4f85d9d2377cd5f80f8f17720
sha1: e137de3d1860122bc067928c65ba289130ebbec6
sha256: b8a6e055f87a6d3e0698f5c7fe3daa99291d6ba7745c9690b87f8260dfe25e5e
sha512: 4cf59b4f82466283ade9c0789befa8dd0d2ff6a35588e5870bd2d0c4abb7e893c9ef2801c5df8d0cadb06d3e58664f09b434a6c9daeb817a3bdd56aa2704f462
ssdeep: 6144:MHA0z9nK6H0ifMPBdLmAExeYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qv:kRRtHTEBdyxeYr75lTefkY660fIaDZkL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196847C07F1650E61C273017D310D8F56BEE72B2AC6EAF16119E7816EE6136D4CBE70A2
sha3_384: 00eafdcb8cc0e422b5ae31a85b7188b1dae09918e5a32140ba5b9a6d6627efddf0a1e3389e0733e325eb24e9c012886c
ep_bytes: b8001040009090bb38de4000b91737db
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Packed.Lazy-10001745-0
FireEyeGeneric.mg.ee7658d4f85d9d23
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
ALYacTrojan.GenericKDZ.102778
Cylanceunsafe
ZillyaTrojan.Padodor.Win32.1671138
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderTrojan.GenericKDZ.102778
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.d18601
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.kaakfa
MicroWorld-eScanTrojan.GenericKDZ.102778
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
SophosMal/Generic-R
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.102778
TrendMicroTROJ_GEN.R03BC0DJQ23
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.102778 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.6Y5R0K
JiangminBackdoor.Padodor.evwa
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Generic.D1917A
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Berbew!pz
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.62E4432421
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DJQ23
TencentBackdoor.Win32.Padodor.kl
YandexTrojan.GenAsa!p1fO5hhCx5A
IkarusTrojan.Win32.Padodor
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment