Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E4713E4B976073568171.mlw
path: /opt/CAPEv2/storage/binaries/04b8ea76661e6f79828cd78a4d5d7f3ea5e0674f23968be8bfa3f16785466e6c
crc32: CF4AD63A
md5: e4713e4b976073568171b81ac1ab535e
sha1: aa1cb6cf9469866d313cf6bdaf38024fb1404a1d
sha256: 04b8ea76661e6f79828cd78a4d5d7f3ea5e0674f23968be8bfa3f16785466e6c
sha512: 3286c9fb6e6f533e14dbb62f3f578895fcbc95c6b58f6c057fa7b05aec6166d4092f044bdd805f8bfd61a2cf1b19d179cbaa43f5e613a9bb5322784326379049
ssdeep: 3072:Sx6+R7JEdc2nmFWK+YOEjeFKPD375lHzpa1P:BUp2nG+PEjeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BA39E9795780FB3CBCD0173418E4AD67F3741E5DAAAC99B1089D38C15EB90C9A3EAD0
sha3_384: 24fc0e27774c4556bffc73c02cfd327daf37ebe638c4410956bbbe129c287a2356c5832a19d1ae0d7ca270effd2903eb
ep_bytes: 90906090909090b800104000bb38de40
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
DrWebBackDoor.Wdozer
MicroWorld-eScanTrojan.GenericKDZ.103285
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!E4713E4B9760
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
ArcabitTrojan.Generic.D19375
BitDefenderThetaAI:Packer.F2DCBEC921
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-32
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.jwbqhu
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Padodor.Win32.706184
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e4713e4b97607356
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.ddfq
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.GenericKDZ.103285
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.PornoAsset!8.6AA (TFE:2:ZGASfuO0gFH)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.f94698
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment