Backdoor

Backdoor:Win32/Padodor.SK!MTB removal

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BFD04DE22402AE3532FB.mlw
path: /opt/CAPEv2/storage/binaries/534d27634790f04f15684c54754ef343b1026b9f951f984189447ee2d5094a54
crc32: D154DF38
md5: bfd04de22402ae3532fb31efe8fe54f6
sha1: 5c529d46e6050f3139dc1c5996a1c2fc29598894
sha256: 534d27634790f04f15684c54754ef343b1026b9f951f984189447ee2d5094a54
sha512: f89a21022f945147eab9f1a2c52bceae12746ce8237797a81363b5b8e76d6151e17df81dbedcb14e3a957d720e6bdb50582c3dd9db8299bf5957c4c06b575fe1
ssdeep: 1536:fY/PCC07tW2lub6O9MJ6FpALF9++kooNduV9jojTIvjrH:fp7tzBofQ++kzNd69jc0vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9A37C6AF233EF71F5E00372301A44DE7A59CC7C72BAD0E3998CD11D226F29953A6952
sha3_384: c72b08f1f86251f16549107d056e8cedc8398f7153e6dc2522045f713010b69b684c053da8c4c5e2c3f733f76eab0829
ep_bytes: 609090909090b80010400090bb38de40
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.103285
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!BFD04DE22402
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1069632
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.6e6050
ArcabitTrojan.Generic.D19375
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.ivxafd
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.103285
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bfd04de22402ae35
EmsisoftTrojan.GenericKDZ.103285 (B)
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.etms
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.GenericKDZ.103285
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.GenericKDZ.103285
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.PornoAsset!8.6AA (TFE:2:dQq3nsYFyrD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.589FBE361E
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment