Backdoor

About “Dropped:Backdoor.Padodor.BJ” infection

Malware Removal

The Dropped:Backdoor.Padodor.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Padodor.BJ virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropped:Backdoor.Padodor.BJ?


File Info:

name: 7E690F199CB6E23B0312.mlw
path: /opt/CAPEv2/storage/binaries/0b8cf89de7d35b08626336e3a07ff1db8f0114740ab5e8b46fb67f217e1e6913
crc32: ADB0E274
md5: 7e690f199cb6e23b03123db5b84c4f01
sha1: fb2aec5808478857e1fe86c6bcf652a8788e5256
sha256: 0b8cf89de7d35b08626336e3a07ff1db8f0114740ab5e8b46fb67f217e1e6913
sha512: d31d83e9fbef9d3ce5647f79ea66eb561a2365017c3d4597a1cacd835f4c20674083f0f1f386a03d79808012d0772ced07da4bde47e1468b71d9276460b95555
ssdeep: 1536:ZlLwbrhcKAY3hqhZmoMjuWM9jPfuiz9VbgZrI1jHJZrR:srmXAyYoMjIjPWiz9Vbgu1jHJ9R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177836BAA21672FF1CB46313A19DA18C7E31D447A05EE8355E0F0C14C127BAF966EB3B5
sha3_384: 6a1791a8b93a01b86f20cace5979d001cbb57f7eb5adbf1913ea4180308b37cb44e277eabdf69fc3c8e42d011975ce3a
ep_bytes: 9067e80000000090905890909005aa3d
timestamp: 2014-05-31 22:06:51

Version Info:

0: [No Data]

Dropped:Backdoor.Padodor.BJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.lh
McAfeeGenericRXVP-YB!7E690F199CB6
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
ArcabitBackdoor.Padodor.BJ
BaiduWin32.Trojan-Spy.Quart.a
SymantecBackdoor.Berbew.F
ESET-NOD32a variant of Win32/Padodor.NAX
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.GenKryptik.kcanbg
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
EmsisoftDropped:Backdoor.Padodor.BJ (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.43791
VIPREDropped:Backdoor.Padodor.BJ
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7e690f199cb6e23b
SophosML/PE-A
IkarusTrojan-Spy.Win32.Qukart
JiangminTrojanProxy.Qukart.hveo
VaristW32/Kryptik.JEE.gen!Eldorado
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew.AA!MTB
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GDataWin32.Trojan.PSE.11RRK8R
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.FFE9BACD21
ALYacDropped:Backdoor.Padodor.BJ
MAXmalware (ai score=81)
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.808478
DeepInstinctMALICIOUS

How to remove Dropped:Backdoor.Padodor.BJ?

Dropped:Backdoor.Padodor.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment