Trojan

Trojan:Win32/Bervod.A removal

Malware Removal

The Trojan:Win32/Bervod.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bervod.A virus can do?

  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Bervod.A?


File Info:

name: 6A1C32156FF887A9282C.mlw
path: /opt/CAPEv2/storage/binaries/272971dcd1d94f8a73fc978f69de4fc4a907a7680e7ddaef6ff6be9b86c024fd
crc32: 14BB4D1F
md5: 6a1c32156ff887a9282ca8b799f301f7
sha1: ec94b9017c1ad0a5ace413deadd8a6bce0698228
sha256: 272971dcd1d94f8a73fc978f69de4fc4a907a7680e7ddaef6ff6be9b86c024fd
sha512: 3c7e2acdc07e8c50b80c5dbe7d8990c80cc48b11971002bb677c07e76d1db56666939ce3ef1f0bd3d9f46d350df71561b51fb0888cdab578760f84abef30d9ab
ssdeep: 1536:mFOVOeEccvncvtROZffNjVMAczNeC9iZlDOVtvhv/2e2S9TkHkjj3w684tp+6:mFcoc1kNF5czND9i7SVtZ/d2QkEjjw41
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAA302D372CC4AC2C452867ECB1E6E78A47E9E5194FC5B574E00358EBEBA8248CD2552
sha3_384: d84a98159535d9c85233eb082e70627589c4626c59dd68e8b63c919f29495546453bb68d8d2aac6336da35599805825a
ep_bytes: 60be009043008dbe0080fcff57eb0b90
timestamp: 2009-10-15 08:27:10

Version Info:

0: [No Data]

Trojan:Win32/Bervod.A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Trojan.GenericKD.69758805
FireEyeGeneric.mg.6a1c32156ff887a9
SkyhighBehavesLike.Win32.Trojan.nc
ALYacDropped:Trojan.GenericKD.69758805
VIPREDropped:Trojan.GenericKD.69758805
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Trojan.GenericKD.69758805
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.17c1ad
BitDefenderThetaAI:Packer.3081BEA61F
SymantecTrojan.Dropper
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.Baidload-6688910-0
KasperskyTrojan-Downloader.Win32.BaiDload.a
AlibabaTrojanDownloader:Win32/BaiDload.bd29026f
NANO-AntivirusTrojan.Win32.BaiDload.flvihi
ViRobotTrojan.Win32.Downloader.308224.E[UPX]
RisingTrojan.DL.Win32.Mnless.foe (CLOUD)
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.SZ
DrWebTrojan.DownLoader4.64092
ZillyaDownloader.BaiDload.Win32.1
TrendMicroTROJ_DLOADR.SMR
Trapminesuspicious.low.ml.score
EmsisoftDropped:Trojan.GenericKD.69758805 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Agent.czcy
WebrootTrojan:Win32/Bervod.A
GoogleDetected
AviraTR/Spy.Agent.SZ
VaristW32/Vanish.A.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.BaiDload
Kingsoftmalware.kb.b.992
MicrosoftTrojan:Win32/Bervod.A
XcitiumTrojWare.Win32.TrojanDownloader.Baidload.~a@225iyw
ArcabitTrojan.Generic.D4286F55
ZoneAlarmTrojan-Downloader.Win32.BaiDload.a
GDataDropped:Trojan.GenericKD.69758805
CynetMalicious (score: 99)
McAfeeArtemis!6A1C32156FF8
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32AdWare.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DLOADR.SMR
TencentMalware.Win32.Gencirc.115d4daf
IkarusBackdoor.WinNT.PcClient
MaxSecureTrojan.Malware.1075206.susgen
FortinetW32/BaiDload.A!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/Bervod.A?

Trojan:Win32/Bervod.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment