Backdoor

Dropped:Backdoor.Padodor.BJ information

Malware Removal

The Dropped:Backdoor.Padodor.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Padodor.BJ virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropped:Backdoor.Padodor.BJ?


File Info:

name: EDBE615697105AD24F2C.mlw
path: /opt/CAPEv2/storage/binaries/c940de1788ac463b990faee06eb51d8ea547eabe6ad9d48b14107a135981a51b
crc32: 784081FC
md5: edbe615697105ad24f2c6ab0fb084763
sha1: 9518aede17e077f70bc4e0905f73fb361ae3c974
sha256: c940de1788ac463b990faee06eb51d8ea547eabe6ad9d48b14107a135981a51b
sha512: 497d4b8ee38c3fecbf16ac946a4deb212df47dd3773f1331ab8bd8523907c7d8c6e1af47fecf667d2e7ae37b3c289c9669e2fc1ac18a52a9fb614b6464dd3a5d
ssdeep: 12288:hDd7bSwwL2bWGRdA6sQhPbWGRdA6sQxuEuZH8WF50+OJ3BHCXwpnsKvNA+XTvZHO:nSwwL2vzecI50+YNpsKv2EvZHp3oWB+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B475BF32FA66D533C4C622F522AD17B1E8AEC1FE173382D3465857E4A2162C386F53D9
sha3_384: 19df50a7b95f23fc9fbfdb8534350d8035d0e68593eb4186dc8a2bc1646363ea0492f71761bfb8b94e8d1d89e7840e9d
ep_bytes: 906090909090b80010400090906a0490
timestamp: 2014-05-31 22:06:51

Version Info:

0: [No Data]

Dropped:Backdoor.Padodor.BJ also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43791
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
CAT-QuickHealBackdoor.Berbew.A6.MUE
ALYacDropped:Backdoor.Padodor.BJ
MalwarebytesGeneric.Malware.AI.DDS
VIPREDropped:Backdoor.Padodor.BJ
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.e17e07
BitDefenderThetaAI:Packer.E1DB93DB21
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.Qukart.kcajlz
F-SecureTrojan.TR/Crypt.XDR.Gen
BaiduWin32.Trojan-Spy.Quart.a
ZillyaTrojan.PadodorGen.Win32.1
SophosTroj/Agent-BGRP
IkarusTrojan.Crypt
JiangminTrojan.Generic.dzrgt
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Padodor.BJ
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GDataWin32.Trojan.PSE.11RRK8R
VaristW32/Agent.HJI.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
Cylanceunsafe
TencentTrojan.Win32.Pornoasset.a
YandexTrojan.PR.Qukart!7x4N/APncCU
SentinelOneStatic AI – Malicious PE
MaxSecureProxy.Qukart.gen
FortinetW32/Qukart.A!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Dropped:Backdoor.Padodor.BJ?

Dropped:Backdoor.Padodor.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment