Backdoor

Backdoor:Win32/Berbew!pz removal

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: CF59AF8068A3E0BDD37D.mlw
path: /opt/CAPEv2/storage/binaries/66149e3c35c3b7f75fa26c06ca41809ff432067fe892ccab21b7d3a3a5c1c9e3
crc32: 0B1180A3
md5: cf59af8068a3e0bdd37db783bd98e346
sha1: 53b4e582bee39635a1aa011df052aa6cb57d6d43
sha256: 66149e3c35c3b7f75fa26c06ca41809ff432067fe892ccab21b7d3a3a5c1c9e3
sha512: 6ea80959fbd0bd2da611a069d60da97664e22b831d50528d6d3ffcd782aec3e73f9b3dfa183d33e16944fffba35d4a8af914153158497b70b36e70c38938df31
ssdeep: 6144:R/wDxP7Sc5TCndOGeKTame6UK+42GTQMJSZO5f7M0rx7/hP66qve6UK+42GTQMJL:RyedOGeKTaPkY660fIaDZkY66+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B1648D1BB16D5E61C6B3017C118D8F5AFEA72328C1EAD1D08AE5848ED5339D50B673B3
sha3_384: ca721a13c0ad2d1b481c5dffd19f5c1024b04e626300561eb7091eda664a193f5fe885edcb764d9990dafde3533530de
ep_bytes: 60909090909067e80000000090909090
timestamp: 1993-01-21 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.304514EE.A.491E17DB
ClamAVWin.Trojan.Crypted-36
FireEyeGeneric.mg.cf59af8068a3e0bd
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOK!CF59AF8068A3
Cylanceunsafe
VIPREGeneric.Dacic.304514EE.A.491E17DB
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.2bee39
ArcabitGeneric.Dacic.304514EE.A.491E17DB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGeneric.Dacic.304514EE.A.491E17DB
NANO-AntivirusTrojan.Win32.Padodor.kandbf
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGeneric.Dacic.304514EE.A.491E17DB (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.1142873
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.erlx
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.15MS2TX
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGeneric.Dacic.304514EE.A.491E17DB
MAXmalware (ai score=80)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:3:7Fd5I0GyygL)
YandexTrojan.GenAsa!p1fO5hhCx5A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.40B3AD2F21
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment