Backdoor

Backdoor:Win32/Berbew!pz information

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 38C3A80AB900EBEEA734.mlw
path: /opt/CAPEv2/storage/binaries/1254e37f8eb19b5c5ed3d78a6b784da890ff2671da07c0fa7aac8803faccb1d6
crc32: 91FA4D89
md5: 38c3a80ab900ebeea7343b0a4c382292
sha1: 261f5fa2079b96282ee5090187ffb64f6aa1964b
sha256: 1254e37f8eb19b5c5ed3d78a6b784da890ff2671da07c0fa7aac8803faccb1d6
sha512: 8c95a0b80a373128ee02293304925547a71080c847b61b7b55086eb8e9144d0880e40d5fe7fc4b1d2766886e28dafb1a94cae72d935c276a2ec682b6ec5fa87b
ssdeep: 1536:47xHQm2qC52Xd4cm52/+M9JkkV1nmvlf:q6FE4c/5JtSvlf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191247DBA78B78EB1C0C51234C6F21458EABD00C9D3F29029A1E5D7887A3B19FD97974D
sha3_384: cccbfe9e749bafd933d31fbb6b28fce7c29ff5e64f9f7cebb05501bd31cdaa6e3c1443b6da7c78ac2e36f6bbc23995fe
ep_bytes: 00000000000000000000000000000000
timestamp: 2005-07-31 11:34:31

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.103870
ClamAVWin.Malware.Qukart-6838239-0
SkyhighBehavesLike.Win32.Generic.dz
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.103870
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D195BE
BaiduWin32.Trojan-Spy.Quart.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Convagent.gen
BitDefenderTrojan.GenericKDZ.103870
AvastWin32:Evo-gen [Trj]
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
EmsisoftTrojan.GenericKDZ.103870 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.IRC.Tdongs
TrendMicroTROJ_GEN.R03BC0DKM23
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.38c3a80ab900ebee
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=80)
Kingsoftmalware.kb.b.934
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmHEUR:Backdoor.Win32.Convagent.gen
GDataTrojan.GenericKDZ.103870
VaristW32/Padodor.F.gen!Eldorado
Acronissuspicious
ALYacTrojan.GenericKDZ.103870
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DKM23
TencentBackdoor.Win32.Padodor.hj
IkarusTrojan.Win32.Padodor
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.HTI!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.2079b9
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment