Backdoor

Backdoor:Win32/Padodor.SK!MTB malicious file

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: CCC5BC59EC48B2586D2D.mlw
path: /opt/CAPEv2/storage/binaries/9827a3d47b480a15f6af9d8017bedc804797dc20ced215fbf9ac6e5f7c2626c2
crc32: E3ADECCC
md5: ccc5bc59ec48b2586d2dffe711b4ebfa
sha1: 67b9cbca39becd73fae20b226fd8a9c239611844
sha256: 9827a3d47b480a15f6af9d8017bedc804797dc20ced215fbf9ac6e5f7c2626c2
sha512: fd6aedbbd9438a37c15503a2aeef247c22ce0b679c21e0a08b10677adf962fbe3ab03e59d99b0611249a1629f1af25bb89eefd5e4ad91301adb9a547e544aab2
ssdeep: 3072:Z5Ozpn0SiolK6u/Mjq1XyIYjQc/1WdTCn93OGey/ZhJakrPF:uzpwO1jfecwTCndOGeKTaG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108C34B1BB2001F61C2D23E77175B8986A61DB1362EF7C5939068B07E2653FDB8E3B584
sha3_384: e9bdb438508e8a1693d9f1e99965a2b147ea75c4a71f21f1de9b41f8f8f2c753208d6ac76a7de1d180bed13ad8f5e69c
ep_bytes: 609090909090b8001040009090bb38de
timestamp: 1993-01-21 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.103285
FireEyeGeneric.mg.ccc5bc59ec48b258
SkyhighBehavesLike.Win32.Malware.ch
ALYacTrojan.GenericKDZ.103285
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a39bec
ArcabitTrojan.Generic.D19375
BitDefenderThetaAI:Packer.780C268C21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.kfgflg
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.23
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.103285 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.erlx
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=82)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.15MS2TX
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!CCC5BC59EC48
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRansom.PornoAsset!8.6AA (TFE:2:dQq3nsYFyrD)
IkarusTrojan.Crypt
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment