Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C991C2857F9DA1948708.mlw
path: /opt/CAPEv2/storage/binaries/dde8494896a6320a4e1874d49f73d8d888cba5c4c82a62c487685433bdb03268
crc32: 5E439CF8
md5: c991c2857f9da194870867c023519657
sha1: 479f9e237ab85797eee2a94f00b7342a9289099d
sha256: dde8494896a6320a4e1874d49f73d8d888cba5c4c82a62c487685433bdb03268
sha512: 2483cade21a7d9078ff6da88dbee4928199139e81a2fa216e352e2549fc63e99e172be16fd8ad1fd13a2a6442466a0be0fefade6a0ae7a3988b08efe5051bfba
ssdeep: 6144:wsC2t059tzCYzk/m7U5j2QE2+g24Id2jFHu:wsLtyHz8iojj+Td20
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E346C6A72450FADC4F002B12E0B97C4E62BBE3B5E5988B314784D1D329BE26CF7E145
sha3_384: cbb381f6a9e26ee956401c9ddff93902db3a422e05a257b3071a5784f8ff1360271a1d5c66d3915db345ae96ce5f1d3b
ep_bytes: 90609067e80000000090905890909090
timestamp: 2016-06-02 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.5
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
FireEyeGeneric.mg.c991c2857f9da194
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.dh
ALYacGenPack:Trojan.Agent.DQQO
Cylanceunsafe
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGenPack:Trojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.5455A2201E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.HangUp.flkhet
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
SophosMal/Generic-R
F-SecureTrojan.TR/Crypt.XDR.Gen
ZillyaTrojan.QukartGen.Win32.1
Trapminemalicious.high.ml.score
EmsisoftGenPack:Trojan.Agent.DQQO (B)
IkarusBackdoor.Win32.Padodor
MAXmalware (ai score=89)
JiangminBackdoor.Padodor.ewpp
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.37ab85
AvastWin32:BackdoorX-gen [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment