Backdoor

Backdoor:Win32/Padodor.SK!MTB malicious file

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E77B775B95311CA749E1.mlw
path: /opt/CAPEv2/storage/binaries/9f8d185b1b7d96afb52a3ecbc349e52079bbfa581342f35888674f075bce35cd
crc32: 7EEA4100
md5: e77b775b95311ca749e16f6947180b8f
sha1: 5f5af2342006dd78cb4547bfa3408cd6d01994cb
sha256: 9f8d185b1b7d96afb52a3ecbc349e52079bbfa581342f35888674f075bce35cd
sha512: 633c5812afffbaafc86c4dd6ef93defdb03b6b96e073d7a75b13bb801ab994fa08ee117818b6ab8c24c9d054bd7652368f82c1b980d6ec9b4f1afdc3632a2d18
ssdeep: 1536:QtWx3hgOa6mOYwwPPE3twk+k5UU9xj1JSGVMLgI+sRQZRkRLJzeLD9N0iQGRNQR5:Q0x3hgOa6mOYwwPPE0k5UExjucMsIVek
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184939DBFF2A07FA3C69003B537DD58FAEF09D538031A9BA5C468867E06573288D35586
sha3_384: 66e9d1b78cd7c28167e3eaf5b40d93b0f9acadaa47ce6ae13b416c6c1b08014bdc9263122366d762a226a9ec1736a1ca
ep_bytes: 90906090909090b800104000bbd0c740
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.5
MicroWorld-eScanTrojan.Agent.DQQO
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!E77B775B9531
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.7
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.5c5c76b5
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.0E93EAB821
SymantecBackdoor.Berbew
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-32
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kg
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPRETrojan.Agent.DQQO
TrendMicroTROJ_GEN.R002C0DL623
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.DQQO
JiangminBackdoor.Padodor.erkj
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DL623
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusTrojan-Downloader.Win32.Berbew
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.42006d
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment