Backdoor

Dropped:Backdoor.Padodor.BJ removal

Malware Removal

The Dropped:Backdoor.Padodor.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Padodor.BJ virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropped:Backdoor.Padodor.BJ?


File Info:

name: 1A0142FD9FB158125482.mlw
path: /opt/CAPEv2/storage/binaries/19afd49fdda87317b5002cc8eb69ed6fc46624dab99fb1301fcd20fe19df7e51
crc32: C417B3E4
md5: 1a0142fd9fb158125482fdd23b84b768
sha1: 222d3ce2179c2066d4136ed02fe7fde4fe657027
sha256: 19afd49fdda87317b5002cc8eb69ed6fc46624dab99fb1301fcd20fe19df7e51
sha512: d1f88ce813c8dca0e7c5c7e284ad5a290ef5e2092092758dd29ac733fd90afde8dae4bad327ecedd03b57638c238b49ab68619b53b2b896c43594e48f7834d81
ssdeep: 1536:KDvKfoC6iKC+vvLKakcMVEt0sbFpnJ/pxZrI1jHJZrR:Ka6iKjnLKdnsvnJxxu1jHJ9R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B836DDB6FE42F72D541027A007A2DE1FBFB706A422A86C95544CE3C7733D18866D3A9
sha3_384: 697ce29a8687e9c5ccfd919754090474824713e2aaa8817467f690dedd34240e446492592870e413150587702b94fd3a
ep_bytes: 9090b800104000bb6c8f40009090b966
timestamp: 2014-05-31 22:06:51

Version Info:

0: [No Data]

Dropped:Backdoor.Padodor.BJ also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
FireEyeGeneric.mg.1a0142fd9fb15812
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.lh
McAfeeGenericRXVP-YB!1A0142FD9FB1
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.2179c2
BitDefenderThetaAI:Packer.FFE9BACD21
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
EmsisoftDropped:Backdoor.Padodor.BJ (B)
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.43791
VIPREDropped:Backdoor.Padodor.BJ
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11RRK8R
JiangminTrojanProxy.Qukart.hveo
GoogleDetected
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Padodor.BJ
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew.AA!MTB
VaristW32/Kryptik.JEE.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacDropped:Backdoor.Padodor.BJ
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Crypt.hag
IkarusTrojan-Spy.Win32.Qukart
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Dropped:Backdoor.Padodor.BJ?

Dropped:Backdoor.Padodor.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment