Backdoor

Backdoor:Win32/Berbew!pz removal guide

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 21D7AC4CC14144A61FC0.mlw
path: /opt/CAPEv2/storage/binaries/8a9616bf270f3aef63b2c4e755ea579a6e9168b4d0f054fdb095f996f0374ea8
crc32: DB63E5F6
md5: 21d7ac4cc14144a61fc012ee6e05d93a
sha1: 041ebd8b159c08bf3b824b1c92490605cbe3b767
sha256: 8a9616bf270f3aef63b2c4e755ea579a6e9168b4d0f054fdb095f996f0374ea8
sha512: 87ce6d9b94893c50c7aee0a3254a5ce942cc713d7b7f8ddfe35edf7e0f0505955f99745388eca7f5a6a5f5587dc00b1589b0d6dd5fe01a9870d4e46a9b442475
ssdeep: 3072:RtSKoa7HsSPYmseA57DxSvITW/cbFGS92TlTTtttSneicdq:OI7HTnA1hCw92TlTTttt5D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126047CEB22270FD2ECC602BE166D0D9F3300D2E5155594BC51B8B15DC16A12AEEFE2B7
sha3_384: 1b371e7e532fd23b5cea94c16bd3d26a260cb75ad5ab35a78c1fdda631b9239aa084ef0b046bb02859da452cf09d524c
ep_bytes: 60909090909067e80000000058909090
timestamp: 2019-02-27 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.kWZ@auBEZAc
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Backdoor.ch
McAfeeTrojan-FVOK!21D7AC4CC141
Cylanceunsafe
ZillyaTrojan.Padodor.Win32.1286074
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Padodor.c9d06169
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.5E4510D81E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Berbew-10013977-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.kWZ@auBEZAc
NANO-AntivirusTrojan.Win32.Padodor.fmrrib
ViRobotTrojan.Win.Z.Padodor.178729.HGU
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.kWZ@auBEZAc (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.kWZ@auBEZAc
TrendMicroTROJ_GEN.R03BC0DLC23
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.bmyl
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitTrojan.ShellObject.EA0F93
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.kWZ@auBEZAc
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLC23
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.b159c0
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment