Backdoor

Backdoor:Win32/Padodor.SK!MTB information

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: F40AEE99019A6B2E96D4.mlw
path: /opt/CAPEv2/storage/binaries/89d62bac00f46913904d0e70904adef6bbbabc6018e961bda0217ae1a0a3f404
crc32: 62AA2489
md5: f40aee99019a6b2e96d42ea34bf8487a
sha1: 0c8b7fa8b6a7368bac2914e4275a706d02716291
sha256: 89d62bac00f46913904d0e70904adef6bbbabc6018e961bda0217ae1a0a3f404
sha512: 8d9b9413f3ceb7a7e49bbcfd63b2a7ad72c1572c0f62cc3e385ded38dda05a45fa48821e7ebca75a2fd8c55202720efa6978cda1b7280efeed70ce8f7af30958
ssdeep: 1536:vC+bgg1JgGwgfdY/jJTPgc/2+kQRQyDbRvwtycORTRQ6mRQQRRQjGmZrhAVK5:T71rw0s1ogReyDbpwoTRBmDRGGurhUI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138A37C7FBB551F63CAD101B9D98B87D26214E274033E89A254B8E17C024FA29927DF73
sha3_384: 86cdb8e02a93126ac578f6a9c8a12bc2d0c1a744b451f0a2366be5ce87eb28b0736ce8666ad192c53542ad3a888a00d8
ep_bytes: 9090b800104000906a04909090909090
timestamp: 2016-06-02 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
FireEyeGeneric.mg.f40aee99019a6b2e
SkyhighBehavesLike.Win32.Generic.nc
ALYacGenPack:Trojan.Agent.DQQO
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Trojan.Agent.DQQO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Trojan.Agent.DQQO
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.8b6a73
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
AlibabaBackdoor:Win32/Padodor.f82d00ab
NANO-AntivirusTrojan.Win32.Padodor.foufls
ViRobotTrojan.Win.Z.Padodor.101376.AYWA
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.HangUp.5
TrendMicroTROJ_GEN.R002C0DKC23
Trapminemalicious.high.ml.score
EmsisoftGenPack:Trojan.Agent.DQQO (B)
IkarusBackdoor.Win32.Padodor
JiangminBackdoor.Padodor.eyaa
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
VaristW32/Pahador.QLFO-8537
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
KingsoftWin32.Hack.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Agent.DQQO
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.Agent.DQQO
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGeneric Malware.bj
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKC23
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
BitDefenderThetaAI:Packer.AF4775D21E
AVGWin32:BackdoorX-gen [Trj]
AvastWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment