Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: B2DF74AA7EA7ABF25E9F.mlw
path: /opt/CAPEv2/storage/binaries/1904f0723da9da7f07e6b1b8fff59bdf844ed38ac33bffe9dc9ec7fd231c3f69
crc32: EF73F152
md5: b2df74aa7ea7abf25e9f6a40a8fffd6f
sha1: 2be6662241f7adaedf3a077dade950fa06ff2aa1
sha256: 1904f0723da9da7f07e6b1b8fff59bdf844ed38ac33bffe9dc9ec7fd231c3f69
sha512: 423b8e72464a8dfcfb6ac64ffae0a97a68e1e60e4c3b999fccaf99309bfac0c26710d27cc5d9fad4461d42f16069f4d05a101b4745528018ec662a44dfdb6174
ssdeep: 1536:fEDK0/2LH6JVac9J+XCY+deSfLKkKHSB4KRmjFLRQpR+KRFR3RzR1URJrCiuiNjH:OK0/2QVa2MCY0LyHa4zpepjb5ZXUf2ib
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B938C6E33900FB2C9D004BBE00A149CF36C9679F29DBEA2099BC60E257795E737D194
sha3_384: e9f68ab723a1c4e551f8bf1826174be51f76683c0285a6a4aba70c63368aceb86fad20d8a61482ab7834dfe18e4ea56c
ep_bytes: 90909090609090b800104000906a0490
timestamp: 2020-07-11 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.5
MicroWorld-eScanMemScan:Trojan.Agent.DQQO
ClamAVWin.Trojan.Crypted-29
SkyhighBehavesLike.Win32.Generic.mc
McAfeeTrojan-FVOJ!B2DF74AA7EA7
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.PadodorGen.Win32.29
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.241f7a
ArcabitTrojan.Agent.DQQO
BitDefenderThetaAI:Packer.56C2618A1E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderMemScan:Trojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.HangUp.fsokoc
AvastWin32:BackdoorX-gen [Trj]
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
EmsisoftMemScan:Trojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
VIPREMemScan:Trojan.Agent.DQQO
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.c
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=83)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMemScan:Trojan.Agent.DQQO
VaristW32/Injector.A.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment