Trojan

TrojanDownloader:Win32/Berbew!pz removal

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: BFEB3087850527A7B450.mlw
path: /opt/CAPEv2/storage/binaries/12ad46fcfffb16553698e7e28d49316cefa24c38131fb7ee6c2c254d58de7c9c
crc32: 7FB4A011
md5: bfeb3087850527a7b450d451acd2803c
sha1: e2835455b71425f34053ca0c2d89354f64040910
sha256: 12ad46fcfffb16553698e7e28d49316cefa24c38131fb7ee6c2c254d58de7c9c
sha512: fccc9989ae7072a92d3cba7d42512a4b09191a83d40d930f33b050aeaa84fa2ccdfb0ad24f7c98a0492cc0b962cd4b4676267515462e0b9f95696d87ddf1297f
ssdeep: 3072:8fA5AXrtAO6SS41C2egyd6DrLXfzoeqarm9mTKpAImA:8fKAbtl6jIydkXfxqySSKpRmA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BED38D1972113E73EFCA2DF52FDEC6C7621E8778C174C9695298941CC03AC43BAB6686
sha3_384: 6ad48f20b2e4504ab3ec41f8af8bcd40a944388f3a100c8809e3ddaf327fb4e2f29e0b38acdba9dc28910c2a6251545c
ep_bytes: 9067e800000000909090589090900563
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.i8Z@aC!4gaf
FireEyeGeneric.mg.bfeb3087850527a7
SkyhighBehavesLike.Win32.Generic.cc
McAfeeGenericRXPE-AP!A0333CC59D88
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.i8Z@aC!4gaf
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.E620A4
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.i8Z@aC!4gaf
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.i8Z@aC!4gaf (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Wdozer
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.exys
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.i8Z@aC!4gaf
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGen:Trojan.ShellObject.i8Z@aC!4gaf
MAXmalware (ai score=85)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:fGiz2IHxOJD)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
BitDefenderThetaAI:Packer.30AA7EDE1E
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.5b7142
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment