Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: CC6960BA25FE3BF3BB23.mlw
path: /opt/CAPEv2/storage/binaries/675010e762dc979f7acb837a99b3dbdf8afb0f68ebc934a5357494079f71b4ab
crc32: ABAD953E
md5: cc6960ba25fe3bf3bb23a818d481f349
sha1: 661a6883bf972a126808bfeb285b493e4f6a2812
sha256: 675010e762dc979f7acb837a99b3dbdf8afb0f68ebc934a5357494079f71b4ab
sha512: e4c2bc9ae23dd36a4ff71736287bad3d0dcac5ce72e48cf08809803fb67017f69c7175f9b200f74dbc4ce5d6d5259bf9bbdfba72722c0c0ac2a4560c7463078c
ssdeep: 1536:rwxnkf+rB9Xy+rnBWX3aImgyXAeor/ZfWujeaDduV9jojTIvjrH:r4nkf+7yeWX3abCeQwujeaDd69jc0vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BA38E83A5A73FA2CBD60BBD270EC8D75109B83D51FDC1210B7C8619191F6B479B7A42
sha3_384: 7440d8ce1b6e4b764351d3ab154793dc658584a0e4f230a1aab5c5626a4ab9b06d6563ec0dd8cb427bc1f1b0216c0322
ep_bytes: 9060909090b800104000bb38de400090
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103285
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!CC6960BA25FE
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.15
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.d17849d0
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D19375
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.jwbprc
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.103285
TrendMicroTROJ_GEN.R03BC0DLJ23
SophosMal/Generic-S
IkarusBackdoor.Win32.Padodor
JiangminTrojanSpy.Convagent.fp
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.GenericKDZ.103285
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.911C0A761E
ALYacTrojan.GenericKDZ.103285
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLJ23
RisingBackdoor.Padodor!8.118 (TFE:5:ostuCj5goYJ)
YandexBackdoor.Padodor!O0zPM3UyhW4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.3bf972
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment