Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BBFB1D193EDE3C03EC85.mlw
path: /opt/CAPEv2/storage/binaries/076a9c0c01a95dd71d655ff1f309cab9cc401fed3c490a4fbf6c5a652d2c422a
crc32: 824D6793
md5: bbfb1d193ede3c03ec857991265076d9
sha1: d679df12465e4c2f3ce01856f5bb2ea29a872428
sha256: 076a9c0c01a95dd71d655ff1f309cab9cc401fed3c490a4fbf6c5a652d2c422a
sha512: 52934a868d17e8d8a0d3fc5ca6e9ea9e97779017029ef6f189f0a3df28b576584a4ade1af42979bea76e3744162b9d6f46e707411225016d880da95e7f1fb8c7
ssdeep: 12288:G4YNp6t3XGCByvNv54B9f01ZmHByvNv5imipWf0Aq:1Sp6t3XGpvr4B9f01ZmQvrimipWf0Aq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3844A2F73DA2EB3CFD409F0913EA495621C9169FB26EDBD6098C00DF9E6959C379090
sha3_384: 10105ff0b271fe9e6cb24fc2c8e30e61381693ad5bd6207c9934427648b71cc640226ebd111e15d763583d7ca9b4511f
ep_bytes: 90906090909090b800104000bbd0c740
timestamp: 2019-02-27 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.5
MicroWorld-eScanTrojan.Agent.DQQO
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.fh
McAfeeTrojan-FVOJ!BBFB1D193EDE
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.Padodor.Win32.1488883
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Agent.DQQO
BitDefenderThetaAI:Packer.924506AE21
SymantecBackdoor.Berbew
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-32
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.Agent.DQQO
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.Win32.Qukart.ya
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.Agent.DQQO (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPRETrojan.Agent.DQQO
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bbfb1d193ede3c03
SophosTroj/Padodor-M
IkarusBackdoor.Win32.Padodor
JiangminBackdoor.Padodor.erkj
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.Agent.DQQO
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.Agent.DQQO
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.Win32.Padodor.gen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.2465e4
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment