Trojan

TrojanDownloader:Win32/Berbew!pz (file analysis)

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: FF39AF465FBA82372E0C.mlw
path: /opt/CAPEv2/storage/binaries/0db5078591d17abb00d8293ebd712a5aa09fdd2f7ca60b866a8ad9601dc60de7
crc32: 859C6DAC
md5: ff39af465fba82372e0cc96e35ab26e1
sha1: d58cc84c7995a897f019f6b7e33375e2e1735d88
sha256: 0db5078591d17abb00d8293ebd712a5aa09fdd2f7ca60b866a8ad9601dc60de7
sha512: 8698948f5371e6adc7beaab216400f0484afd798a33e85a299adc55e6f8e2df231318c2e820aa01e88fd003f4a58bab1d8bb15ecec1000c4666393cd73da371d
ssdeep: 3072:B+Cqn/a8U3g08TwMx6C0+lc802eS5pAgYIqGvJ6887lbyMGjXF1kqaholmtbCQV1:ELnC5w5x6C1lc85dZMGXF5ahdt3b0668
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A648CABA2408F92C383C0F1D5C959D6B61DB2FA72AE84A1C5DD83CFB177E1A42755C0
sha3_384: 06339d3f89f9bb41a5e389339eb49efc77cf04f2a40f424234079d5d50d7c6f7ef2c71dcbfd05d084a2c23ae1abe9e3b
ep_bytes: 60909090909090b80010400090909090
timestamp: 1976-08-18 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.t8Z@a0kuefc
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fh
McAfeeTrojan-FVOJ!FF39AF465FBA
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.QukartGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.c7995a
ArcabitTrojan.ShellObject.E4A0DA
BitDefenderThetaAI:Packer.AB80913321
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.t8Z@a0kuefc
NANO-AntivirusTrojan.Win32.Padodor.ixfuwg
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.t8Z@a0kuefc (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPREGen:Trojan.ShellObject.t8Z@a0kuefc
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.dqkd
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.15MS2TX
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Qukart!8.13257 (TFE:1:HGzWgvMnmLU)
YandexTrojan.GenAsa!p1fO5hhCx5A
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment