Backdoor

What is “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 32CFB1F0340BE8DAA5CD.mlw
path: /opt/CAPEv2/storage/binaries/c48fa2c5efbb03e5c101982e930986f6d6e659197c35956556b910e0cc1e30d8
crc32: 24E7765D
md5: 32cfb1f0340be8daa5cdc10ca7dc831e
sha1: e72d05f85a97501f1bf42e86c690921993c07309
sha256: c48fa2c5efbb03e5c101982e930986f6d6e659197c35956556b910e0cc1e30d8
sha512: 614a566d950ca0cf38e667390c0f260ded299c309db4e427284833e17719e0808b4883d711edcaaa756d9d6439f74bee26985a5d67e4a0e8b667c8ffbc67da18
ssdeep: 1536:zqNmKVOjr9GEwYxZw89V6rbaz/vF10PIf54GjzHvly:zGmKZEw18vT/MABnvly
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B624279A1CB96EB3C2C8423C10E51735E48125CE73B1F49EDE65E684D6BB2DC85B9F20
sha3_384: bf9f10588614fe1f538d498dad3898a13a68f41c070b444eac25fb6a6b1f17f74101e6eba156bd4c87ecde9ac5022a93
ep_bytes: 00000000000000000000000000000000
timestamp: 2005-07-31 11:34:31

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
MicroWorld-eScanTrojan.GenericKDZ.103870
FireEyeGeneric.mg.32cfb1f0340be8da
SkyhighBehavesLike.Win32.Generic.dz
McAfeeArtemis!32CFB1F0340B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1834686
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D195BE
BaiduWin32.Trojan-Spy.Quart.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generickdz-10013340-0
KasperskyHEUR:Backdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103870
NANO-AntivirusTrojan.Win32.Tdongs.kdjgfj
AvastWin32:Evo-gen [Trj]
TencentBackdoor.Win32.Padodor.hj
EmsisoftTrojan.GenericKDZ.103870 (B)
DrWebBackDoor.IRC.Tdongs
VIPRETrojan.GenericKDZ.103870
Trapminemalicious.moderate.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Padodor
VaristW32/Padodor.F.gen!Eldorado
Kingsoftmalware.kb.b.982
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmHEUR:Backdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1YSHFBU
GoogleDetected
Acronissuspicious
ALYacTrojan.GenericKDZ.103870
MAXmalware (ai score=85)
Cylanceunsafe
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.HTI!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.85a975
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment