Backdoor

Backdoor:Win32/Padodor.SK!MTB information

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E01425FE47EBFC86FF21.mlw
path: /opt/CAPEv2/storage/binaries/b31d1b20ecc743ccb9b23f48a73d7657724a34c0f20c9af90bf4da5e7d71882b
crc32: 1F7D2D16
md5: e01425fe47ebfc86ff218fde99b0ebdb
sha1: 5e72d87870eda365cc828c81b799bb6665d28b27
sha256: b31d1b20ecc743ccb9b23f48a73d7657724a34c0f20c9af90bf4da5e7d71882b
sha512: f4c07f6182a98cde75e2ba43e6bb244f5965b2f24539b565d09209fc076dd02c758f94690219ae5fe8798feccf49d228cc794f5b54946e5d1bcacdc136449b83
ssdeep: 1536:bv7wEnY8tm2nY0jcle27RwhN4LuII++oRRQdR+KRFR3RzR1URJrCiuiNj5QkMMWs:bvbYKzY0a/W2FFRedjb5ZXUf2iuOj22T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C936A3665571F72CCC101B5640AC9BB7A29D0BC2E3CE59E5486E56E02CFFE425E8B83
sha3_384: 37d454718ebc105803c69bb7318e9800480dc75626272e1b588d5076daab5aca491f380369485b16c5cfe8030153a30d
ep_bytes: 60909090909090b80010400090909090
timestamp: 2020-07-11 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
FireEyeGeneric.mg.e01425fe47ebfc86
SkyhighBehavesLike.Win32.Generic.mc
ALYacGenPack:Trojan.Agent.DQQO
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.Padodor.Win32.1219052
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Trojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.B245410121
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.fmedry
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodor-M
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.HangUp.5
VIPREGenPack:Trojan.Agent.DQQO
Trapminemalicious.high.ml.score
EmsisoftGenPack:Trojan.Agent.DQQO (B)
SentinelOneStatic AI – Malicious PE
GDataGenPack:Trojan.Agent.DQQO
JiangminBackdoor.Padodor.l
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitGenPack:Trojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!E01425FE47EB
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.870eda
AvastWin32:BackdoorX-gen [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment