Backdoor

Backdoor:Win32/Berbew!pz removal

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: C16F01DC8C4AF6630E1C.mlw
path: /opt/CAPEv2/storage/binaries/dc12d5ffae786d583d231c76a53d7eb316ed999a532c033a74a8edba5fbdec9f
crc32: 1CD55E2E
md5: c16f01dc8c4af6630e1c19cff93b8e98
sha1: 96595d5dda9fc08e5d102cf1249a095216a0bfcd
sha256: dc12d5ffae786d583d231c76a53d7eb316ed999a532c033a74a8edba5fbdec9f
sha512: f41270bf0355eed48feeec5af9f715e608dba9fa93e45a925240c90667853ec58015bbf7fdf6926bd1aa8587aea1cf03d802b3efe9179b00d1d74e8c37194cd3
ssdeep: 6144:LuDww3Okofbxfj6EneYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qve6UKV:SDwsOkoTJDneYr75lTefkY660fIaDZk5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E646A06E1765D70C7D3917F200C9BAF3ED76A28C5FAE92A09F2828AD6535C14F57093
sha3_384: 4b49bcb4c0b5ddfa875346995db4327bb3b6a5407f0e80fcc97d138d02adbc6bd669e71c82bb6eed2732f22e2e2c6127
ep_bytes: 906090909090b8001040009090906a04
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.u8Z@aOGzovi
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeTrojan-FVOJ!C16F01DC8C4A
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.u8Z@aOGzovi
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.dda9fc
ArcabitTrojan.ShellObject.ECE127
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.u8Z@aOGzovi
NANO-AntivirusTrojan.Win32.Padodor.ivbifr
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
EmsisoftGen:Trojan.ShellObject.u8Z@aOGzovi (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.dgnd
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.ED13E05F21
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.PornoAsset!8.6AA (TFE:3:qo76B0vtTv)
YandexTrojan.GenAsa!p1fO5hhCx5A
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment