Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BD3D7650B260C7FC48C9.mlw
path: /opt/CAPEv2/storage/binaries/2d0507918e19bd436559ecca8c8b2c98471def8ef40c2cd7fa6a51d811dd2d01
crc32: 97B528E5
md5: bd3d7650b260c7fc48c95ad201f896a1
sha1: e64784ccef155dd8883d738721cc84c57c695e9f
sha256: 2d0507918e19bd436559ecca8c8b2c98471def8ef40c2cd7fa6a51d811dd2d01
sha512: 7ad7e846eaff0bda758b3d5bea87b00eb91c12cc90527497b844d15ea88183872a44e5453b51d0b2cb9e22616eba81643e604ccf338efd0c26a7ef56182ea7c7
ssdeep: 3072:UOXHiwEfdnvlTrCeycpwoTRBmDRGGurhUI:lX8RvFZym7UI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DA38D0EB3885FB2C1A332B1A61FF5D2EB16D338D259D4D2952C916D2342E27D63B5C2
sha3_384: bd6a2845903457ef47ebd4b7972eea9abb3c4317720801d2380b6930e48f03d872407a9f0f5dfd8ca4c5159650da8342
ep_bytes: 909060909090b8001040009090bbd0c7
timestamp: 2016-06-02 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DQQO
SkyhighBehavesLike.Win32.Generic.nc
ALYacTrojan.Agent.DQQO
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Agent.DQQO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderTrojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecBackdoor.Berbew
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.foufls
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
SophosTroj/Padodor-M
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.HangUp.5
ZillyaTrojan.Padodor.Win32.1330206
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bd3d7650b260c7fc
EmsisoftTrojan.Agent.DQQO (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
JiangminBackdoor.Padodor.esac
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.Agent.DQQO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGeneric Malware.bj
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.2F95F9791E
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.cef155
AvastWin32:BackdoorX-gen [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment