Backdoor

What is “Backdoor:Win32/Berbew!pz”?

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: D96E8398046AC249BE39.mlw
path: /opt/CAPEv2/storage/binaries/4c1915fa6d7c3e84b16682d6312f461e51c25475b6008a74f9fe027771b13cd4
crc32: C6E69B86
md5: d96e8398046ac249be39313d531e8734
sha1: fd68527785550e92ae063323cf00332b0dd92116
sha256: 4c1915fa6d7c3e84b16682d6312f461e51c25475b6008a74f9fe027771b13cd4
sha512: 63b9df299ff0f06fe77aa16455cec6c128fc8af5b61e27856de5157465bb3f9652b6cc1cc4c5895e7b36aaa72506661311e5ef21d40e14d2748a80bbdd3f0d63
ssdeep: 768:NV8NqJl0nxyZ6mawqK8UWx1gXJggDjBrBf3JbWQZ6+FlTgUHqMqf/1H5nTXdnhK:NTHOqWnSJhD1r93JbWQZLxKvltR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E145BE17636EE6FDBE130B632752352D0EC00C620AE42DC559882DE6A7F50549E9AF3
sha3_384: 04269c010c3a653ad1980e829863bd133e31ad6ff5d9e33fc55d327fb0544adfdd7bd39a994657abc5ddf35292d4d08e
ep_bytes: 00000000000000000000000000000000
timestamp: 2009-09-08 11:34:31

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Berbew.m!c
MicroWorld-eScanTrojan.GenericKDZ.103336
SkyhighBehavesLike.Win32.Generic.dz
McAfeeGenericRXAA-FA!D96E8398046A
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.103336
SangforSuspicious.Win32.Save.a
BitDefenderTrojan.GenericKDZ.103336
Cybereasonmalicious.785550
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Qukart-6838239-0
KasperskyHEUR:Backdoor.Win32.Padodor.gen
AlibabaBackdoor:Win32/Berbew.a4423de8
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SophosMal/Generic-S
BaiduWin32.Trojan-Spy.Quart.a
DrWebBackDoor.IRC.Tdongs
TrendMicroTROJ_GEN.R03BC0DK723
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d96e8398046ac249
EmsisoftTrojan.GenericKDZ.103336 (B)
IkarusTrojan.Crypt.XDropper
GoogleDetected
VaristW32/Nymaim.FY.gen!Eldorado
Kingsoftmalware.kb.a.999
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitTrojan.Generic.D193A8
ZoneAlarmHEUR:Backdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1BROO7W
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.GenericKDZ.103336
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DK723
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.3E08!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment