About Trojan Download.Berbew
Download.Berbew is a Trojan Horse that
attempts to download Backdoor.Berbew from the
Internet and execute it on the local system. This
Trojan was spammed to a large number of
individuals in an email message claiming to be
from Citibank Accounting or E-Loan.com.
Download.Berbew typically arrives as an
attachment with a .pif extension, such as:
- web.da.us.citi.heloc.pif
- wellsfargo.biz.jsessionid.pif
- www.citybankhomeloan.htm.pif
- E-Loan-Appraiser-Results.pif
- www.usbank.com.stats.personals.balance.pif.pif
- www.fdic.com.fraud.security.pif.zip (Note:
This is a password protected zip file.)
When Trojan.Download.Berbew runs, it does the
following:
- Downloads Backdoor.Berbew from a remote
server and saves it to %System%. The server
from where the file is downloaded may vary,
and one location we have seen is saher.by.ru.
The file name in %syste% may also vary. An
example of one we have seen is rtdx32.exe.
- Runs Backdoor.Berbew.
Also known as: Downloader-DI,
TrojanProxy.Win32.Webber.10, Troj/Webber-A
Trojan Download.Berbew Removal
Automatic Removal: Using BPS
Spyware & Adware Remover to detect and remove
Download.Berbew AUTOMATICALLY!
Manual Removal:
Not Available.
Detection and Removal Instructions for Trojans
|