Trojan

TrojanDownloader:Win32/Berbew!pz removal instruction

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: F73D9FEC4945656FF2C6.mlw
path: /opt/CAPEv2/storage/binaries/8c6f69e9d2292d54e322ab09e417e10d44952f197a9b58812a02acfa1a905126
crc32: 5C16D0FA
md5: f73d9fec4945656ff2c63905bd8970ea
sha1: e5bc5c28c2532462afc24d65fdc2d71fb74813ca
sha256: 8c6f69e9d2292d54e322ab09e417e10d44952f197a9b58812a02acfa1a905126
sha512: 8aa6d27897a6f19f6fe3496cec27bd36fea9a9192f0fd93ef0f5f549fb7b0481ca90a7d309f99f14314e3b6a477c4921931e9329efb7d236e4ee75d352bc024f
ssdeep: 6144:dQ2LgAy1ZLMo66gSUmKyIxLDXXoq9FJZCUmKyIxLX:dQ2LgAOZLMot32XXf9Do3+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163646A6AD2EC6E53CB45CEFB94810FF3A6560AD586ECB59E360C86B469468317C30F70
sha3_384: 14c47b757368b88bbf387964ca879a51eca2797071ba0472baca2d8eae4049f9e9b63bd8012d6997386b9bb602463ec0
ep_bytes: 90609090909090b800104000bb38de40
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
CyrenCloudW32/Agent.FTJ.gen!Eldorado
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
CynetMalicious (score: 100)
FireEyeGeneric.mg.f73d9fec4945656f
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeTrojan-FVOJ!F73D9FEC4945
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.873223
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.e84d5454
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.8c2532
ArcabitTrojan.Generic.D19375
BitDefenderThetaAI:Packer.A23B208121
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.jzfafg
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
Ad-AwareTrojan.GenericKDZ.103285
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPRETrojan.GenericKDZ.103285
TrendMicroTROJ_GEN.R002C0DKU23
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.erja
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
GDataTrojan.GenericKDZ.103285
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.GenericKDZ.103285
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKU23
RisingBackdoor.Padodor!8.118 (TFE:1:X6rxYYcFM4D)
YandexBackdoor.Padodor!A5nRMmhQe3Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment