Backdoor

Backdoor:Win32/Berbew!pz information

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Binary compilation timestomping detected

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: E60D974FB34B21307183.mlw
path: /opt/CAPEv2/storage/binaries/c85b582cddc46439941e6fc16eeda60ad67c4809b3e1730a750b5c60d60c6018
crc32: C3D24874
md5: e60d974fb34b21307183f897251de1dc
sha1: 7e16af098227761dfe8ecbdec033d496e53ca074
sha256: c85b582cddc46439941e6fc16eeda60ad67c4809b3e1730a750b5c60d60c6018
sha512: 745ed4b3e2e583baaf14540a4705e9e3de2c9b0c207c114fae3b5cfe2f111da307c641c413b04a01efd250eb06ae6446744c8676b291e44901794540617a16c8
ssdeep: 768:7lixLkP3pyIHMXlpPS5ZyneeekIt/xjTFuaU4ZUSJa/1H5kZ0YXdnhorx5VFmcjO:7liu3bs1miePRxTmn+5kzoQYx+QS9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146446B3AD6F80F91F89703F24436D6D2DD174479C26F94CEE27CC2C8662B91DA8B6A50
sha3_384: 1e813d5baefea063105ad350987848dc3a313bdd2b0b61360ec6509029eafd409f71dd6bd02ba1f7cadc9c8a9da1020d
ep_bytes: 00000000000000000000000000000000
timestamp: 2028-06-02 07:39:47

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Berbew.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen2.4699
FireEyeGeneric.mg.e60d974fb34b2130
SkyhighBehavesLike.Win32.Generic.dz
McAfeeArtemis!E60D974FB34B
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Berbew.d99be4a6
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Dropper.Berbew-9106192-0
KasperskyHEUR:Trojan.Win32.Convagent.gen
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:TrojanX-gen [Trj]
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SophosMal/Generic-S
BaiduWin32.Trojan-Spy.Quart.a
TrendMicroTROJ_GEN.R03BC0DAN24
Trapminemalicious.high.ml.score
IkarusBackdoor.Win32.Berbew
GDataWin32.Trojan.Agent.PX7FVA
GoogleDetected
VaristW32/Heuristic-CO3!Eldorado
Kingsoftmalware.kb.a.1000
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
MicrosoftBackdoor:Win32/Berbew!pz
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Berbew.R608115
Acronissuspicious
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R03BC0DAN24
TencentMalware.Win32.Gencirc.10bf9042
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.HTI!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.982277
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment