Trojan

TrojanDownloader:Win32/Berbew!pz removal guide

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: CB8B17FBAD37A6EEB034.mlw
path: /opt/CAPEv2/storage/binaries/6536a1cd7c39580e9a052c7a5752249ccd958ca6c42cc546d4dea8959d6b0daf
crc32: 485B29C7
md5: cb8b17fbad37a6eeb03421cf4a5ce550
sha1: 242249b8b0d5183241ab6a56054edd05ca781178
sha256: 6536a1cd7c39580e9a052c7a5752249ccd958ca6c42cc546d4dea8959d6b0daf
sha512: 7ae88cb1e3270456f84f2f33ce8c722963269fa0a4a3070a8808d2eb9d5655c2a44a1df6c887ed7248dec064af167e1aae2db94aa98cad2b3680f2cf71cb1612
ssdeep: 6144:1zrcSN4YRpgqUmKyIxLDXXoq9FJZCUmKyIxLX:1TNjZ32XXf9Do3+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA648D47D2ED5E13CA46C67780C10EF2A5564ACA8EE364EE360C98B0AF5B931FC7C951
sha3_384: b807bcc612700c89fbc6ee224014ed9245557d47ead98b180a7c25e48d1d3595b7b0d7eda7c57df9945c140cff23d9fb
ep_bytes: 60909090909067e80000000090909058
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.t8Z@ae0D4Vj
ClamAVWin.Trojan.Crypted-36
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOK!CB8B17FBAD37
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1011686
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.8b0d51
BitDefenderThetaAI:Packer.A23B208121
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.t8Z@ae0D4Vj
NANO-AntivirusTrojan.Win32.Padodor.jwhasn
AvastWin32:Padodor-V [Trj]
TencentTrojan.Win32.Qukart.ya
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.t8Z@ae0D4Vj (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.t8Z@ae0D4Vj
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.cb8b17fbad37a6ee
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ShellObject.t8Z@ae0D4Vj
JiangminTrojanProxy.Qukart.dvru
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.E66A9A
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftTrojanDownloader:Win32/Berbew!pz
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:1:X6rxYYcFM4D)
YandexBackdoor.Padodor!A5nRMmhQe3Q
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment