Backdoor

Should I remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: A476FE93A1ABC38AED8D.mlw
path: /opt/CAPEv2/storage/binaries/7af752d4dcec2cc2a4cc9c85f41ad51137f2133a2eb46c84dbdd21e68a287d65
crc32: 45125DA0
md5: a476fe93a1abc38aed8d951ad4a61ab4
sha1: 4a015fd52b7a7ee3a8f63f4766842d248e3d67a4
sha256: 7af752d4dcec2cc2a4cc9c85f41ad51137f2133a2eb46c84dbdd21e68a287d65
sha512: 27e3bbb3263d6f65af82cbfd493cfa1db45edbc0c42e80c59c9a6574cbf7b7d7af1af693a044af7169a4d2e2c5a1f48617e63e97ca466c3b5e1cd6cdaf486255
ssdeep: 1536:7ClKFX1kMhF6l46fGUxabO6v61btjx52PTiEQQsezRQAR+KRFR3RzR1URJrCiuip:7BUOAoUxabO6v6htjPcWEBs0eAjb5ZXg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15793AE97B14E1F93DF8509BC7E8B90AEA51795BE923EE45641A3803C2053B3E32F9D41
sha3_384: d88fce7d500cc40aa0593de30ea586805a66d3c712f2646792dda36be65f9481b534c2a576d4fb60380a1ffbd73f97d1
ep_bytes: 60909090909090b800104000bbd0c740
timestamp: 2020-07-11 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DQQO
SkyhighBehavesLike.Win32.Generic.mh
ALYacTrojan.Agent.DQQO
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.PadodorGen.Win32.29
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.52b7a7
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.fnvhic
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.HangUp.5
VIPRETrojan.Agent.DQQO
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a476fe93a1abc38a
SophosTroj/Padodor-M
IkarusBackdoor.Win32.Padodor
GDataTrojan.Agent.DQQO
JiangminBackdoor.Padodor.l
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!A476FE93A1AB
MAXmalware (ai score=86)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.B245410121
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment