Backdoor

Backdoor:Win32/Padodor.SK!MTB information

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E4322FF5E299DA130F12.mlw
path: /opt/CAPEv2/storage/binaries/72503f82658852bd058c0522cbb8e7f6ad4eaca04a8bba7553dec1f823490318
crc32: E9D23985
md5: e4322ff5e299da130f123abbeb692de9
sha1: f3b74e4323ff7b51af2ea7679392b37ba31f0821
sha256: 72503f82658852bd058c0522cbb8e7f6ad4eaca04a8bba7553dec1f823490318
sha512: 9e9000838dbcb66dc6e66fdbada9f7e3ee6b6a01a8c9e43148554adaa8054a0acdc3dbd50889cf6ab2463bff5aa1a11b428b22baf9066be494389b5f6d973bfb
ssdeep: 3072:tKoOkcP9NTd9NMd9CbKPV2Ace2SJdEN0s4WE+3S9pui6yYPaI7DX:tKoORP9N2922DENm+3Mpui6yYPaI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ABD3AF2BAD6D2F63C6C206F3350A19626F19D9F211344CE304DEC01B167FAB9A1F95E6
sha3_384: b9cc733488ff98329e634ae1ff2eb9df48ae9837881341aa21973e6166c4b6dd7d3c49d784ed330f06a7953dd2c107d7
ep_bytes: 90b8001040009090bbd0c7400090b95d
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.5
MicroWorld-eScanGenPack:Trojan.Agent.DQQO
FireEyeGeneric.mg.e4322ff5e299da13
SkyhighBehavesLike.Win32.PWSZbot.cc
McAfeeGenericRXHD-SL!BD4CA221F04E
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.323ff7
ArcabitGenPack:Trojan.Agent.DQQO
BitDefenderThetaAI:Packer.AB6D347E21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Qukart-10012701-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGenPack:Trojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kg
TACHYONBackdoor/W32.Padodor
EmsisoftGenPack:Trojan.Agent.DQQO (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGenPack:Trojan.Agent.DQQO
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusBackdoor.Win32.Padodor
JiangminBackdoor.Padodor.eyag
VaristW32/Pahador.QLFO-8537
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1G33IXO
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGenPack:Trojan.Agent.DQQO
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment