Backdoor

Backdoor:Win32/Padodor.SK!MTB removal tips

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 9099617AD1755676621A.mlw
path: /opt/CAPEv2/storage/binaries/8a5a7f0eb786b18ce89a5716adea5e000ff56ff53b44ba853a005959cf48f23a
crc32: 5C5D225F
md5: 9099617ad1755676621a359ef99bdfca
sha1: 86b72eb20933d5e2f2ebbb23e6922bc6f7b4a07d
sha256: 8a5a7f0eb786b18ce89a5716adea5e000ff56ff53b44ba853a005959cf48f23a
sha512: e4b8b34081ed99eff9ccd381ccf16d236d8b14367026d606de4cada5004e7df398447dcbbac4371889e75c2cd95ca3d1fee94c3f0b9181c2c684ceec6000b58f
ssdeep: 1536:WHo6PpvJsOKMZfFGorIoA8E0CxAowzrI6scmfKcjXR13ZugQ7NgEX2fOOQ/4BrGD:yoapxsS9moABbKowzKjXI1NNSU/4kT0y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132938E0FB4183EF2C6B043737717EC5FB35BA922D279C9283BA8855C2217954D27AE24
sha3_384: f92a09552b2aaec9e01142b5a49b78826f66082d76ed8c6a07501babf3a253c8d3cf3a405316462cb71c82684d28a7c0
ep_bytes: 60909090909090b8001040009090906a
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebBackDoor.Wdozer
MicroWorld-eScanGenPack:Trojan.GenericKDZ.103285
ClamAVWin.Trojan.Crypted-28
FireEyeGeneric.mg.9099617ad1755676
SkyhighBehavesLike.Win32.Generic.nc
ALYacGenPack:Trojan.GenericKDZ.103285
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Trojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
ArcabitGenPack:Trojan.Generic.D19375
BitDefenderThetaAI:Packer.8AF09F8821
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGenPack:Trojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.kedanv
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.km
EmsisoftGenPack:Trojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
TrendMicroTROJ_GEN.R03BC0DKL23
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.erkc
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=87)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.GenericKDZ.103285
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!9099617AD175
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DKL23
RisingBackdoor.Berbew!8.115 (TFE:2:9yvesnxXv6N)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.20933d
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment