Backdoor

Backdoor:Win32/Berbew!pz removal guide

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 48ED6D89EBA4B84C0BA5.mlw
path: /opt/CAPEv2/storage/binaries/96a6f294c2968cc399145b52e5f31948aefbfea0a3dcf568b269f44618498783
crc32: E031FA25
md5: 48ed6d89eba4b84c0ba5dc04e81735de
sha1: d8381ea7fb8b864530aa570ad3ec38912a5c7d73
sha256: 96a6f294c2968cc399145b52e5f31948aefbfea0a3dcf568b269f44618498783
sha512: 2d2ecfc10861d0e7263dc49fff1738facffba2f4d1f007837893def943f1703b3ab38c5d5db7e5d7e958949678d393910b59f79fd5ab72b61b6b22c284882adc
ssdeep: 6144:dpjEMfxUacECeYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qve6UK+42GT9:8K+uCeYr75lTefkY660fIaDZkY660f28
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C848C8BB3611EF1C253417D200D9F767EE72228D6EAD365B9E5814EE223AC44F67093
sha3_384: 44474e94f332d53301d2c75926fa995f9edc709bc116ba19a4e61136a88fc16fa88eefc12ac78894e7117cd735f9ed56
ep_bytes: 67e8000000009090589090900563a040
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.102778
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeGenericRXPE-AP!BCA6E0D9C5A3
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.102778
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderTrojan.GenericKDZ.102778
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.7fb8b8
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Packed.Lazy-10001745-0
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.jznpmh
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
TACHYONBackdoor/W32.Padodor
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.48ed6d89eba4b84c
EmsisoftTrojan.GenericKDZ.102778 (B)
IkarusTrojan.Win32.Padodor
JiangminBackdoor.Padodor.evwa
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitTrojan.Generic.D1917A
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.62E4432421
ALYacTrojan.GenericKDZ.102778
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment