Backdoor

Backdoor:Win32/Padodor.SK!MTB malicious file

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 96DB3FBCD1BC3079898B.mlw
path: /opt/CAPEv2/storage/binaries/a79bc93157fee91296489c19b93129082c38eb3d0f612abaf86997fa7ee97dca
crc32: 1CF346E7
md5: 96db3fbcd1bc3079898b277b235154bd
sha1: 83893a2e14cc81724fd36617769367d664a59b36
sha256: a79bc93157fee91296489c19b93129082c38eb3d0f612abaf86997fa7ee97dca
sha512: 562810b8f59261975bfd02ad7d6671ec8096e2e7fae937dc9f32c1ae4ab5a8ffe829ef13e09b8b2bd93bf1c611c53771ec9c9e3f94c65790b53f05f640561d70
ssdeep: 1536:+W5zR3VMUYG+oiq9HNk+zUqRm+41CUsRQGRkRLJzeLD9N0iQGRNQR8RyV+32rR:+WjVM/olHNk+zM+eGSJdEN0s4WE+3K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C937DC261A63FA6E18207F46C3BA5DB7A24E9750B25B5E871F9C01C1227D78933FD90
sha3_384: 21756bb6343bc62136f10e432f624336d8bf6c2d916bb9a09d66e07ad3dcc8430409d0d3ed6a42e1951882db89361c47
ep_bytes: 90909067e80000000058909090909005
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
FireEyeGeneric.mg.96db3fbcd1bc3079
SkyhighBehavesLike.Win32.Generic.nc
ALYacGenPack:Trojan.Agent.DQQO
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Trojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.e14cc8
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Qukart-10012701-0
KasperskyBackdoor.Win32.Padodor.gen
AlibabaBackdoor:Win32/Padodor.da457d4f
NANO-AntivirusTrojan.Win32.Padodor.foufls
ViRobotTrojan.Win.Z.Padodor.95744.DMPA
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
EmsisoftGenPack:Trojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.HangUp.5
TrendMicroTROJ_GEN.R002C0DKA23
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
JiangminBackdoor.Padodor.ewpp
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXHD-SL!5443E2AA96F0
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKA23
TencentBackdoor.Win32.Padodor.kg
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
BitDefenderThetaAI:Packer.2ABBEDA021
AVGWin32:BackdoorX-gen [Trj]
AvastWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment