Backdoor

About “Dropped:Backdoor.Padodor.BJ” infection

Malware Removal

The Dropped:Backdoor.Padodor.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Padodor.BJ virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropped:Backdoor.Padodor.BJ?


File Info:

name: 82C2EC3F9EE0E0620022.mlw
path: /opt/CAPEv2/storage/binaries/847f341d68be407c3a27920198ca02cccd43b04d392f356492ea546fc1ea95c3
crc32: 55DA838D
md5: 82c2ec3f9ee0e06200229ad59848b8e8
sha1: 287c171d00134980d568d5e32f4da00d54461c8c
sha256: 847f341d68be407c3a27920198ca02cccd43b04d392f356492ea546fc1ea95c3
sha512: 7e498bf9749ef86461a52b9d3c229f7133a42b89792310832945ee8a3fe0721e9aa3efcb9409f367fe50b35b4d612909013a30e5ba5827b0762e9234752f6e31
ssdeep: 1536:QyO8GoGI2t56HbQwXzRtapflZrI1jHJZrR:68Gonj7QIR2lu1jHJ9R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183837C5FD5FA9FF1C595CE34201B01D2EB2B742822BBE154E414D0CE2EB3A2893B9359
sha3_384: ac1e836f8f161637f9f4847c5549920633fe7781c2bb635b5b3bd7205b8ea198d399250805a6b055de90fee2e78539ac
ep_bytes: 60b8001040009090bb6c8f4000b9ec1b
timestamp: 2014-05-31 22:06:51

Version Info:

0: [No Data]

Dropped:Backdoor.Padodor.BJ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.h!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
FireEyeGeneric.mg.82c2ec3f9ee0e062
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.lh
ALYacDropped:Backdoor.Padodor.BJ
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Berbew.36d
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitBackdoor.Padodor.BJ
BitDefenderThetaAI:Packer.FFE9BACD21
VirITWorm.Win32.Berbew.G
SymantecBackdoor.Berbew.F
ESET-NOD32a variant of Win32/Padodor.NAX
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Convagent-10013337-0
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Crypt.hag
EmsisoftDropped:Backdoor.Padodor.BJ (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.43791
VIPREDropped:Backdoor.Padodor.BJ
TrendMicroTROJ_GEN.R002C0CLK23
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanProxy.Qukart.hveo
VaristW32/Kryptik.JEE.gen!Eldorado
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew.AA!MTB
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GDataWin32.Trojan.PSE.11RRK8R
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXVP-YB!82C2EC3F9EE0
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CLK23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan-Spy.Win32.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.d00134
DeepInstinctMALICIOUS

How to remove Dropped:Backdoor.Padodor.BJ?

Dropped:Backdoor.Padodor.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment