Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 5981AC2CD1FAEA6896CA.mlw
path: /opt/CAPEv2/storage/binaries/e640028f2039a264c9c63ad0f607a5f04b257882a86971bcc6fd4567715f6f6d
crc32: F7F8753A
md5: 5981ac2cd1faea6896ca23791ccd0f0a
sha1: 9368ea08e7ee7e2692a089065a1d891bc98b0c34
sha256: e640028f2039a264c9c63ad0f607a5f04b257882a86971bcc6fd4567715f6f6d
sha512: 7a0bced7452653da0330ea7afeb1e57432d7e53eda02692837953773dd66d6619bb71b8ed26f9ecc983a00b3d6100a299866f28b4cf3a4f082dee09ec4ed7c3e
ssdeep: 1536:gUd1eqE8nsB7yDkLB6PobvgqIg3mevXsWMR1bZ00fVUUsRQFlRkRLJzeLD9N0iQx:tTsBD/VIovAHseTSJdEN0s4WE+3K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7936CEA66C92EA1FCD502B1740AC0D57E1DF2B3322DE4D11CB4909D67939299EB6FC0
sha3_384: 5c43a9c9dbb511ef92c8fc6192105f8d0537e76fe646f13a9e8a0078f32733ce1830d3428027efe6920a9d922d84ccfa
ep_bytes: 90609067e80000000090589090909005
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
ClamAVWin.Trojan.Qukart-10012701-0
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOK!5981AC2CD1FA
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.8e7ee7
ArcabitGenPack:Trojan.Agent.DQQO
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGenPack:Trojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kg
EmsisoftGenPack:Trojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.HangUp.5
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5981ac2cd1faea68
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.ewpp
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.2ABBEDA021
ALYacGenPack:Trojan.Agent.DQQO
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment