Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: AD924A64007269841B23.mlw
path: /opt/CAPEv2/storage/binaries/b391b6c149d8f28bb32d3c0194b2ee7aba549726271134a7dd75d6026a59a14b
crc32: 17AA661F
md5: ad924a64007269841b2337a641353196
sha1: 85acce379897b360bab07e4b621ee9156d29cbd0
sha256: b391b6c149d8f28bb32d3c0194b2ee7aba549726271134a7dd75d6026a59a14b
sha512: 1b88507ded285691eb9c5a7b9fe1b6e4df37fa543902b5e4f950c669a3145e0b61e383bd32a18d78b9ab0ce5d670cdd53e7e16239b933ac3449523974d84defe
ssdeep: 12288:0yL4waSXyi6t3XGCByvNv54B9f01ZmHByvNv5imipWf0Aq:l7JJ6t3XGpvr4B9f01ZmQvrimipWf0Aq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C846B1AB2C52F71DF580BF0133E6288A29C9178FFAAEDBD4095C81DF5EA915C379181
sha3_384: 0e4e73392e46beb806c92e7ff0574ca7b6b2d5d390327be309a05d88f44f3efc70dde24f72518174aaab6dacd66e7195
ep_bytes: 909090909060b8001040009090906a04
timestamp: 2019-02-27 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
FireEyeGeneric.mg.ad924a6400726984
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.fh
McAfeeTrojan-FVOJ!AD924A640072
Cylanceunsafe
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGenPack:Trojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
AlibabaBackdoor:Win32/Padodor.26f029e5
NANO-AntivirusTrojan.Win32.Padodor.flrnxz
ViRobotTrojan.Win.Z.Padodor.407557.CBY
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
EmsisoftGenPack:Trojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.Padodor.Win32.559846
TrendMicroTROJ_GEN.R002C0DK523
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
JiangminBackdoor.Padodor.esac
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.924506AE21
ALYacGenPack:Trojan.Agent.DQQO
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
MalwarebytesPadodor.Backdoor.Bot.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DK523
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
MaxSecureBackdoor.Win32.Padodor.gen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.79897b
AvastWin32:BackdoorX-gen [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment