Trojan

TrojanDownloader:Win32/Berbew!pz removal guide

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 9C602F20950451F5C6A0.mlw
path: /opt/CAPEv2/storage/binaries/4de5f6065cb34a70304306a0190f33038a911e79c35d2988156a945ae4f7169a
crc32: 6A0C3D0B
md5: 9c602f20950451f5c6a02244d42bde7b
sha1: 3699787b8dd0ca9ea21cea5b0c833f045bc90318
sha256: 4de5f6065cb34a70304306a0190f33038a911e79c35d2988156a945ae4f7169a
sha512: f1732ab634ff3bfcf817294d49b4779addee82899ece600c5046f1a4a4479e4b84d72f08ef98efa2a73b0e7abf8e4d745df0e0969341acc8ee18b69b06538b80
ssdeep: 6144:iQfviSmVbM73/fc/UmKyIxLDXXoq9FJZCUmKyIxLjh:iQ3ivH32XXf9Do3i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D747B0EE1EE6EE3CA61C67744F14EF3A602C2D68EE4609E768C9474694E83A3C7D550
sha3_384: f84c66d7e42d654dadd5d5230bf48ea671fb38fd1970e58db42ac212146b5c9355d47ad1bfbee868538161dcea00a963
ep_bytes: 9090b8001040006a04909090905f9090
timestamp: 1977-12-31 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.v4Z@aqH1LVc
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
McAfeeGenericRXPE-AP!4A57335A2AEE
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1846963
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.b8dd0c
ArcabitTrojan.ShellObject.EC7A7A
BitDefenderThetaAI:Packer.7D87752521
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.v4Z@aqH1LVc
NANO-AntivirusTrojan.Win32.Padodor.jwbyny
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.v4Z@aqH1LVc (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPREGen:Trojan.ShellObject.v4Z@aqH1LVc
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.exys
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.v4Z@aqH1LVc
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:J4OVvmnx5dB)
YandexBackdoor.Padodor!A5nRMmhQe3Q
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment