Backdoor

Should I remove “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: C59DD9537DE4B9141530.mlw
path: /opt/CAPEv2/storage/binaries/1c751fc760957c4da7c778ab1e5bb06fddf1ac541cf3ffb73d70443fd222cc90
crc32: 1DDC3244
md5: c59dd9537de4b91415308325e8c69ccb
sha1: 50feddf5464af2f2938b52cb8fc460f4b88e9ec0
sha256: 1c751fc760957c4da7c778ab1e5bb06fddf1ac541cf3ffb73d70443fd222cc90
sha512: 71800a8a8b6ee8bdcd3d77de8a7bf837253f7eed90fee14632fe3deb35bbea05aaadc067e5474b513ec14547c7c5880e35ba25a9c90383105c6c48dd7406c6fa
ssdeep: 6144:3sWs+GjL4cqTCndOGeKTame6UK+42GTQMJSZO5f7M0rx7/hP66qve6UK+42GTQMI:8BLIedOGeKTaPkY660fIaDZkY660ffL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA947C0BB1655E21C253037E200E8F573EE7A368D5EAD16418EEB14EE113AD4CBE7993
sha3_384: 94393468bf20b3aef8ca39c341f2c3d189c9a473374baf7e4bff104f97f67a3383898020d6c4d27bebccebd8f796d34c
ep_bytes: 90909060909067e80000000090909090
timestamp: 1993-01-21 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.z8Z@aCZnhbe
ClamAVWin.Trojan.Crypted-29
FireEyeGeneric.mg.c59dd9537de4b914
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.gh
McAfeeGeneric Malware.bj
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.z8Z@aCZnhbe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
ArcabitTrojan.ShellObject.E7FD12
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.z8Z@aCZnhbe
NANO-AntivirusTrojan.Win32.Padodor.iuvgzf
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.23
EmsisoftGen:Trojan.ShellObject.z8Z@aCZnhbe (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.erlx
GoogleDetected
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.15MS2TX
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.67C3781A21
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:3:DNXmOcx9QQS)
IkarusTrojan.Crypt
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.5464af
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment