Backdoor

What is “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: D1362C6554EBF4D65D94.mlw
path: /opt/CAPEv2/storage/binaries/235ae18007c41bd762a3e7c4e945048195e755305859b41972eec3052c8e164a
crc32: 4131E8CD
md5: d1362c6554ebf4d65d94f982de128354
sha1: b1d60332db2c43e25a5a2233d12aca315b0edad8
sha256: 235ae18007c41bd762a3e7c4e945048195e755305859b41972eec3052c8e164a
sha512: d3ddc474ff8bf528f1566e026077ae173665d3f5bc0fc199b196e9173e255d67cb9aa87792df72f6ef02aed4ec2b74e96f717d57678346b68cb4462d5f28e753
ssdeep: 3072:zRqbGT/kTz84VUtz6q25TUeOZl2NkzwH5GJks8WYlOWe7VsayDZVZev1N:zEbGEzhOz6hQ9zwZ9s8SZq/svL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193148D3E711C0E73C8D506F5693F86D466E5F17A0A679C49D08B90EF036BEC9627B282
sha3_384: 40f4b1005543f9c4eb7708398514b8ad9bbcca61610620f80a0d9d6daf72cbd6952dec86703f6a21a4aa77f3329306a2
ep_bytes: 909090906090b800104000909090906a
timestamp: 2019-02-27 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.l0Z@a8rAQKh
FireEyeGeneric.mg.d1362c6554ebf4d6
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Trojan.ShellObject.l0Z@a8rAQKh
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.l0Z@a8rAQKh
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-29
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.l0Z@a8rAQKh
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.l0Z@a8rAQKh (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.Padodor.Win32.757706
Trapminemalicious.moderate.ml.score
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.eupb
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitTrojan.ShellObject.E4AB1F
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.l0Z@a8rAQKh
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!D1362C6554EB
MAXmalware (ai score=85)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.AD28A4ED1D
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.2db2c4
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment