Backdoor

Backdoor:Win32/Berbew!pz malicious file

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: F9262953EED29DDCCC10.mlw
path: /opt/CAPEv2/storage/binaries/012db7a453245534ebe322ef855c371bc3f1a4c5d4b95d65144d24a4b440745f
crc32: 6AB39851
md5: f9262953eed29ddccc10b4e420ad0d47
sha1: f2f79e8b8e5da36bf8f376f7f94d4757228d5e23
sha256: 012db7a453245534ebe322ef855c371bc3f1a4c5d4b95d65144d24a4b440745f
sha512: fdaa3905ca1cdfea6c8332b167ac64b46c2a43d110bc005ae4f0bcf398673001bd44d48b2fcb519f27420ec62ccdfcfdf5d81393989e15cdd6b24b38dc1eeb9b
ssdeep: 6144:NecCxbZTfE3eYr75lHzpaF2e6UK+42GTQMJSZO5f7M0rx7/hP66qve6UK+42GTQ+:AHx+3eYr75lTefkY660fIaDZkY660f28
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16484AD6BB2655E21C7630CBC2C0D8F563EE7622CC2EAD16119EE834EE5539C50F6B193
sha3_384: ddac1548a3ac091f4e99884b641183bfa6e2bb623a454a3f81c769870f7bcb4f9d34b6bb523c68031560e8e8a2d41210
ep_bytes: 67e800000000905890909090900563a0
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.x8Z@ayMulS
FireEyeGeneric.mg.f9262953eed29ddc
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeGenericRXPE-AP!506292826A6B
Cylanceunsafe
VIPREGen:Trojan.ShellObject.x8Z@ayMulS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.99ef2e55
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.ShellObject.E7E46D
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.x8Z@ayMulS
NANO-AntivirusTrojan.Win32.Padodor.ixdkve
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.x8Z@ayMulS (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.2279090
TrendMicroTROJ_GEN.R002C0DLM23
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.evwa
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.62E4432421
ALYacGen:Trojan.ShellObject.x8Z@ayMulS
MAXmalware (ai score=87)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLM23
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
YandexTrojan.GenAsa!p1fO5hhCx5A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment