Trojan

TrojanDownloader:Win32/Berbew!pz removal tips

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: CB6E71135E91022FA85E.mlw
path: /opt/CAPEv2/storage/binaries/de2928a1b77bf37d84787a3a3f353295c14c5d06c8b55fe6ef2c207ac18af106
crc32: D41519E4
md5: cb6e71135e91022fa85e6617a812d449
sha1: 0c4d16dad118a33cbf8319d06ab1412aaf4732b3
sha256: de2928a1b77bf37d84787a3a3f353295c14c5d06c8b55fe6ef2c207ac18af106
sha512: 52e62c10a786ac7a7594838122dac575829a2657a95b44a63262ff8746302001b7c4dcd5fead44cc5aa01b50666335d2980afc4af2cdfbc82d80128fb75546ba
ssdeep: 6144:hwV1YScCxF888888889yW5LRlUivKvUmKyIxLDXXoq9FJZCUmKyIxLpmAqkCcoMD:uDX888888889pZoivKv32XXf9Do3+IvK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139848D06E2DF3F53CE81C6BB48C14DF6E656C2D99AE464FE321C82B86A438393C75552
sha3_384: 55c344a98e459ef63f16e245c9f222353d896eb8050275e78e1a526bd13f9c2bc599e1080725293e069dd2bd2812e60d
ep_bytes: 9090b800104000906a04909090909090
timestamp: 1991-09-09 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.wSZ@a8YIsUn
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeGenericRXPE-AP!819D7BCB21BD
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.wSZ@a8YIsUn
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.ad118a
ArcabitTrojan.ShellObject.E22C9D
BitDefenderThetaAI:Packer.D5CDFBDD21
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.wSZ@a8YIsUn
NANO-AntivirusTrojan.Win32.Padodor.ivqfby
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.QukartGen.Win32.1
EmsisoftGen:Trojan.ShellObject.wSZ@a8YIsUn (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.ezeq
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.18H44AG
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:8UjqtdnNZgS)
YandexBackdoor.Padodor!A5nRMmhQe3Q
IkarusBackdoor.Win32.Padodor
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment