Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C852E84090576BD0D2AB.mlw
path: /opt/CAPEv2/storage/binaries/bf3b446165332f8998a456212ab142260e41df1c0cc90878f873b57d985e1f92
crc32: 159507C9
md5: c852e84090576bd0d2ab7ab10b6fa723
sha1: 70e28c85d49fa85be3be5a07ef62565d626b4bd6
sha256: bf3b446165332f8998a456212ab142260e41df1c0cc90878f873b57d985e1f92
sha512: 00bfd60973476b4d20336d8191514dd2a6657cd56fe2722e2d4b40a229159842ccfdeb63b85b3d591245bf48123d43a226bef29485dd806d8dc3fd5f5a63a661
ssdeep: 3072:8+Mc0XKtwd8Pz3RFGTNXeoSJdEN0s4WE+3S9pui6yYPaI7DX:n90XKtU8Pz3GxORENm+3Mpui6yYPaI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189D3CFABB3691F71C5D002BC2E5B08F8D7E9E539123CCCA355AC905E234A275933E1DA
sha3_384: 84f558562cdf325a7d7e03b2329d14cfe66f3158e38b5dc019c945acb6f700091f05c6a285b2d161a53059e98b4eafd2
ep_bytes: 60b8001040009090bbd0c74000b9d166
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Qukart-10012701-0
SkyhighBehavesLike.Win32.Generic.cc
ALYacTrojan.Agent.DQQO
Cylanceunsafe
VIPRETrojan.Agent.DQQO
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
SymantecBackdoor.Berbew
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
AlibabaBackdoor:Win32/Padodor.84107ecc
NANO-AntivirusTrojan.Win32.Padodor.foufls
MicroWorld-eScanTrojan.Agent.DQQO
AvastWin32:BackdoorX-gen [Trj]
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.Padodor.Win32.2311257
TrendMicroTROJ_GEN.R03BC0DLP23
FireEyeGeneric.mg.c852e84090576bd0
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.eyag
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
KingsoftWin32.Hack.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.Agent.DQQO
ViRobotTrojan.Win.Z.Padodor.131072.CSQU
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1G33IXO
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXHD-SL!5AA5826D0D76
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLP23
TencentBackdoor.Win32.Padodor.kg
YandexBackdoor.Padodor.AF
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
BitDefenderThetaAI:Packer.AB6D347E21
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.5d49fa
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment