Backdoor

Dropped:Backdoor.Padodor.BJ removal guide

Malware Removal

The Dropped:Backdoor.Padodor.BJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Padodor.BJ virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropped:Backdoor.Padodor.BJ?


File Info:

name: 3709D8CF55E1EBD294E5.mlw
path: /opt/CAPEv2/storage/binaries/3ac079100cccd6a4ac46a7e77145efa0b658e00e5d3d428d28ab9fc842049265
crc32: 58A26EA8
md5: 3709d8cf55e1ebd294e598915d9c4c6a
sha1: 72b7af7f2efcead5b4a849eea57561b35cc65b92
sha256: 3ac079100cccd6a4ac46a7e77145efa0b658e00e5d3d428d28ab9fc842049265
sha512: 4e73aabbe0a807f8b5e6cc780325963de4bcd3cf7d64d20f1e383918ffe7a9d484627a5adfde500a5718df7475f1b4924fa98dd54fe461355d5ec9eb96783d57
ssdeep: 1536:smbLICOFVRJdhNPDuxIESEQXZrI1jHJZrR:XwtnvhNPwZ5Mu1jHJ9R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7837D9A62300FF3C58603B5155A59D3E7BAEF2D41B6C58E15A4C20E032FB58EDF9392
sha3_384: 1064bf86cc21c945ebe25e90033d4d9d2d78efa42ae6d29820ae45ded529cc8996cd073d0390ab68a6d6a835ea220536
ep_bytes: 9067e80000000090909090589005aa3d
timestamp: 2014-05-31 22:06:51

Version Info:

0: [No Data]

Dropped:Backdoor.Padodor.BJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.lh
ALYacDropped:Backdoor.Padodor.BJ
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Spy.Quart.a
VirITWin32.Padodor.V
SymantecBackdoor.Berbew.F
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
ClamAVWin.Malware.Convagent-10013337-0
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderDropped:Backdoor.Padodor.BJ
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
MicroWorld-eScanDropped:Backdoor.Padodor.BJ
AvastWin32:TrojanX-gen [Trj]
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
EmsisoftDropped:Backdoor.Padodor.BJ (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.43791
VIPREDropped:Backdoor.Padodor.BJ
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3709d8cf55e1ebd2
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11RRK8R
JiangminTrojanProxy.Qukart.hveo
GoogleDetected
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitBackdoor.Padodor.BJ
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew.AA!MTB
VaristW32/Kryptik.JEE.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXVP-YB!3709D8CF55E1
TACHYONBackdoor/W32.Padodor
VBA32BScope.Backdoor.Berbew
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentTrojan.Win32.Pornoasset.a
IkarusTrojan-Spy.Win32.Qukart
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.EZNP!tr
BitDefenderThetaAI:Packer.FFE9BACD21
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f55e1e
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Obfuscate.FakeEp.DYN(dyn)

How to remove Dropped:Backdoor.Padodor.BJ?

Dropped:Backdoor.Padodor.BJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment