Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BED669910545DA7B3C1E.mlw
path: /opt/CAPEv2/storage/binaries/5f0f4203a46015dc60d35ad16f619ddb4ae8b0e068703c9ce8541ec8b0692a78
crc32: CFB2029E
md5: bed669910545da7b3c1e20a38a58653b
sha1: eaaebf79b24862653c3676d1b4f380468a63f5be
sha256: 5f0f4203a46015dc60d35ad16f619ddb4ae8b0e068703c9ce8541ec8b0692a78
sha512: 51bf7f294ba7dc95abfc8c61d51cc06542fa25645b6a7d248514b72a80d6a01b67cb149edc820ca484adde83cc46a1eb6359c6d81e7d790b58c0d25f78965dd8
ssdeep: 3072:NHPJTr9mCIB/R5OvXpp57GBcYH8fo3PXl9Z7S/yCsKh2EzZA/z:VRrOwXb57GBcYHgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106B37D3EB6529FA7C3C3027A31015FD57F14A064ABFEC5E24898C01F5677E6CA23A1A5
sha3_384: 93d80644833a597fd91f647671e13fc56e6bb1f5d51ec6b32452f3d6d37fa8545f79c5e3b8662309ad5e33b9593dac89
ep_bytes: 90909060b8001040009090bb38de4000
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOJ!BED669910545
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D19375
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Packed.Barys-10002063-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
MicroWorld-eScanTrojan.GenericKDZ.103285
AvastWin32:Padodor-V [Trj]
TencentTrojan.Win32.Qukart.ya
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bed669910545da7b
SophosML/PE-A
IkarusTrojan.Win32.Padodor
JiangminBackdoor.Padodor.eybw
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.GenericKDZ.103285
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.9F7E7E0821
ALYacTrojan.GenericKDZ.103285
MAXmalware (ai score=86)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:sru23FZbUHP)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.9b2486
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment