Backdoor

Backdoor:Win32/Berbew!pz removal

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 4B1A174C52C09FEEA64C.mlw
path: /opt/CAPEv2/storage/binaries/6188af5781a1fcfd92ebf0eab6266b26dfc4c120a359d88e31c7fab764393a4b
crc32: 782E95DF
md5: 4b1a174c52c09feea64c544aeb40337b
sha1: e1d0594cc600faf45d930c8374b07e9e4e4e1949
sha256: 6188af5781a1fcfd92ebf0eab6266b26dfc4c120a359d88e31c7fab764393a4b
sha512: b3f20039928dba05efa32dc2152e3764e46a8069c03cfede1929ac692246fff06c029d7c1a8df24c50eaee46c2a8ac435a5cf9a6d2c233e78f30d0b3fc209eb0
ssdeep: 6144:No49vlGWEXeYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qve6UK+42GTQMH:a49aXeYr75lTefkY660fIaDZkY660f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7648C0EB1758DD1F693007D900D8F163EEB2228D5EAD3A289E6459EE7276C31F63093
sha3_384: f993a8426101259f482005b726f4c58f6d8e7f6c5b335a133786aeaeb00a62ed5c2f6cdb6ef97e6197b49de0cc231232
ep_bytes: 909090609090b80010400090906a0490
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
ClamAVWin.Trojan.Crypted-29
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOJ!4B1A174C52C0
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.16
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.fea45927
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.ShellObject.ECE127
BitDefenderThetaAI:Packer.ED13E05F21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.u8Z@aOGzovi
NANO-AntivirusTrojan.Win32.Padodor.jwnbwm
ViRobotTrojan.Win.Z.Padodor.327680.LPS
MicroWorld-eScanGen:Trojan.ShellObject.u8Z@aOGzovi
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.u8Z@aOGzovi
TrendMicroTROJ_GEN.R002C0DL723
EmsisoftGen:Trojan.ShellObject.u8Z@aOGzovi (B)
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.denm
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
KingsoftWin32.Hack.Padodor.gen
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DL723
RisingBackdoor.Berbew!8.115 (TFE:2:UcHyz6q6Y7K)
YandexTrojan.GenAsa!p1fO5hhCx5A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.cc600f
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment