Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 137D1E1E92E51C0C1982.mlw
path: /opt/CAPEv2/storage/binaries/519fab0745981414b1491788a3092c8358c7d8f63f604fd3549b0d9281cf92dc
crc32: BF1516D1
md5: 137d1e1e92e51c0c19823d32ddb8f680
sha1: b865cfea2f07611daa390dde34b2024a237a03a8
sha256: 519fab0745981414b1491788a3092c8358c7d8f63f604fd3549b0d9281cf92dc
sha512: f6281f4b27f1f06783100fe3dc7363dce60d50e3c2b10b49b27c0a0538555da1b9c8ef3b41c8f0c3f2a3433fbb0d21d60375fdea3f79120a7b83669d3dfb60d3
ssdeep: 3072:+rXY0mdJiqhC1inzo7UOaZeO203H/6TC+qF1SsB1bw4AVRrd9:+80mXiGRVsO9C81NBy9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FC39D2BB7568F62CE9537B5110AD9CD221094FC45A1FAF04CEA80FB234F51778BB6A4
sha3_384: 693691a31e418f3e0ba8c081930ea34e243f082ab32e11c803d8ccca5d9ac87638ef9c7bee6f89fd56156fe2b0bb244d
ep_bytes: 909060909067e8000000009090589090
timestamp: 2023-04-07 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
SkyhighBehavesLike.Win32.Generic.cc
ALYacGenPack:Trojan.Agent.DQQO
MalwarebytesPadodor.Backdoor.Bot.DDS
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a2f076
ArcabitGenPack:Trojan.Agent.DQQO
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Berbew-10013977-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGenPack:Trojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.ffxkaz
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGenPack:Trojan.Agent.DQQO (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.137d1e1e92e51c0c
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.euzh
VaristW32/Pahador.QLFO-8537
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGeneric Malware.bj
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.29F999361D
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment