Trojan

TrojanDownloader:Win32/Berbew!pz (file analysis)

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: 1BAA22730582D6729A9B.mlw
path: /opt/CAPEv2/storage/binaries/dbab3c808725648dfe201ff9aa1aa884e06c4be410fe2781163b3e1141956489
crc32: 296A4DC8
md5: 1baa22730582d6729a9baefbef8ae5ad
sha1: bb6912bd05aab8c80ba0319f94adff96edfb7c34
sha256: dbab3c808725648dfe201ff9aa1aa884e06c4be410fe2781163b3e1141956489
sha512: f85c6558113b9bdb4d0fbad6472a78ef9ce70b4b312467fc135fe421db124c7664506a1bb0ad433f19c62c5136b062c256b15be501c3b08f87eb8bc60f3918c7
ssdeep: 1536:zl9ymMKuW3A4/IrjcNpHjR4O1Oer6DnxWRVkeyyVr3iwcH2ogHq/i352S:zlAmo4/IE72O1lAw3kremwc/gHq/e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DA3AD7BA290BDB6D5090634FABB4586F732D0F4B6FB4C91692351C6109F22133BE8B5
sha3_384: 63333fdfcbea4730b0852a8905594cfbd7d6c7199d4705e062121d82d79676b545466b8ebe7a953b551f38955effb3e0
ep_bytes: 6090b800104000909090906a04909090
timestamp: 1977-12-31 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.g4Y@aqH1LVc
ClamAVWin.Trojan.Obfus-38
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOJ!1BAA22730582
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g4Y@aqH1LVc
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.d05aab
BitDefenderThetaAI:Packer.8DF46C7B21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g4Y@aqH1LVc
NANO-AntivirusTrojan.Win32.Padodor.jvdrls
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.g4Y@aqH1LVc (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.QukartGen.Win32.2
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1baa22730582d672
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ShellObject.g4Y@aqH1LVc
JiangminBackdoor.Padodor.exys
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.E531CF
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftTrojanDownloader:Win32/Berbew!pz
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.g4Y@aqH1LVc
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:J4OVvmnx5dB)
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment