Backdoor

Backdoor:Win32/Berbew!pz removal guide

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: CB8FCD41057721D6B813.mlw
path: /opt/CAPEv2/storage/binaries/3d21010da80978192953e7886a5e0f0c4057b0dcc380047ad010d4a2a99dcaa3
crc32: 809556A8
md5: cb8fcd41057721d6b8135430dc159814
sha1: 6e57be6aecb50952757c726e19f8b5c42be0db9d
sha256: 3d21010da80978192953e7886a5e0f0c4057b0dcc380047ad010d4a2a99dcaa3
sha512: a0cd0c1e7c01b318a063d92b650373793421212f76e45b454df8d45d1f336d61853d2427a7196a8c72cd2026db004090059b31a38cfe4388510b27cf714e6899
ssdeep: 24576:4afyvzecrHPh2kkkkK4kXkkkkkkkkhLX3a20R0i:4afyvKcrXbazR0i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157258D13FA6B9D32C06E0A35623F8F358559CCE5AF5701E329D4EAB1AAB11C794342F1
sha3_384: a856a206ec240aacd936c26efe596c647502eed78ac708e92164408bada3ecd92e55fabbe430bce1b62e7b00af8c6f85
ep_bytes: 909060909090b8001040009090906a04
timestamp: 2021-04-04 22:06:51

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.h!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.cb8fcd41057721d6
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.fh
McAfeeTrojan-FVOJ!CB8FCD410577
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Berbew.36d
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.aecb50
ArcabitBackdoor.Padodor.BJ
BitDefenderThetaAI:Packer.B7CF6C1E21
SymantecBackdoor.Berbew.F
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
EmsisoftDropped:Backdoor.Padodor.BJ (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.HangUp.43791
VIPREDropped:Backdoor.Padodor.BJ
TrendMicroTROJ_GEN.R03BC0CLN23
SophosTroj/Agent-BGRP
IkarusTrojan-Spy.Win32.Qukart
JiangminTrojan.Generic.dzrgt
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GDataWin32.Trojan.PSE.11RRK8R
VaristW32/Agent.HJI.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacDropped:Backdoor.Padodor.BJ
TACHYONBackdoor/W32.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CLN23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojan.PR.Qukart!7x4N/APncCU
SentinelOneStatic AI – Malicious PE
MaxSecureProxy.Qukart.gen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment