Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: ADFAA08A2778A5B17678.mlw
path: /opt/CAPEv2/storage/binaries/6b105f970e1658ca429b009bcfbb47a7beb6ef1e01c4f52d8f661ceb01dd2c83
crc32: 6638BB2D
md5: adfaa08a2778a5b17678e458601d59a5
sha1: 34023f7a5532882bf93a1790fecffb424dfccb2b
sha256: 6b105f970e1658ca429b009bcfbb47a7beb6ef1e01c4f52d8f661ceb01dd2c83
sha512: bbba0282e54f74850066c5b75ee3afc39754e48acd16d7357be45f398cbf13c477a173f1e73a05cf349928536391d9b675b2293b7847714906164d784f101dbf
ssdeep: 3072:S8wkppdtQYDxKey4pwoTRBmDRGGurhUXvBj2QE2HegPelTeIdI7jFHu:uup/DxhSm7U5j2QE2+g24Id2jFHu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161347C6E720A1FEAD5C032F12F379496BA3BCD78725A449310B88D5D0297D17C2BE2B5
sha3_384: 9442651493c8cace9cd34894d10facf684dd9b8e1fd4c7d21960d4377c9bdd25a0d8f8f0f2c008ba2b3787c3e4990308
ep_bytes: 60909090b800104000bbd0c740009090
timestamp: 2016-06-02 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.DQQO
ClamAVWin.Packed.Lazy-10001745-0
FireEyeGeneric.mg.adfaa08a2778a5b1
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.dh
McAfeeTrojan-FVOJ!ADFAA08A2778
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.8
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.9d1cc389
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a55328
ArcabitTrojan.Agent.DQQO
BitDefenderThetaAI:Packer.5455A2201E
SymantecBackdoor.Berbew
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodor-M
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
VIPRETrojan.Agent.DQQO
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.DQQO (B)
IkarusBackdoor.Win32.Padodor
JiangminBackdoor.Padodor.ewpp
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.Agent.DQQO
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.Agent.DQQO
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment