Backdoor

Should I remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: AEB15D1C8183868B0CC2.mlw
path: /opt/CAPEv2/storage/binaries/b93c20af02341af7555f3c077aca99d422fbec8923d0964836a75c5c68adab68
crc32: 6680C2BF
md5: aeb15d1c8183868b0cc23d9f15a016f8
sha1: c9db9a84df4ec20effc104d39729e8c39798b1ee
sha256: b93c20af02341af7555f3c077aca99d422fbec8923d0964836a75c5c68adab68
sha512: 4887726c50039cb4ebf131dd22065311332b5aaf442e7d8df976698eef70f1e065bdd4f224117bea0ac597ff277c2742a769c88e07d27ebe5b42352b2c5c806b
ssdeep: 6144:IAUAjvSeQT4EQtifWwE9eYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qveQ:PUAmb4EQtiC9eYr75lTefkY660fIaDZ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A647A06A1729D62C763347D514D9F6A3EF3232CC5EAD16A0EE2958EE6D39C00F67093
sha3_384: f34aebcf44a038e395bde7f33716c03ebf4abb663e3297921ccf14eb04afb133cd472663989f47f3bb765dc37e3db2a6
ep_bytes: 90909090906067e80000000090905890
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.ShellObject.u8Z@aOGzovi
FireEyeGeneric.mg.aeb15d1c8183868b
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
ALYacGen:Trojan.ShellObject.u8Z@aOGzovi
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.u8Z@aOGzovi
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.ED13E05F21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.u8Z@aOGzovi
NANO-AntivirusTrojan.Win32.Padodor.ivhdoz
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
EmsisoftGen:Trojan.ShellObject.u8Z@aOGzovi (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.dexd
GoogleDetected
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitTrojan.ShellObject.ECE127
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXPE-AP!D5A8CE0F2818
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:2:xj4tAqEbGWH)
YandexTrojan.GenAsa!p1fO5hhCx5A
SentinelOneStatic AI – Malicious PE
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.4df4ec
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment