Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: D6934A7F9958C2F5BD83.mlw
path: /opt/CAPEv2/storage/binaries/c09c39655b2183410bda9e47be7b7f5d036a68177563f0fe5e8b23841eb45d80
crc32: 30A410DB
md5: d6934a7f9958c2f5bd83b3964847f5a5
sha1: 81705b190070abeb4089aeb49298f70d6d7c1cd8
sha256: c09c39655b2183410bda9e47be7b7f5d036a68177563f0fe5e8b23841eb45d80
sha512: d8b752204d7375293b61c38f044840a6e9cbb891b26dba331ce2f481c0fa42eff6c529fbfdee8162eb9122485510684347a1d31f013eb5cb5cd9809336f46101
ssdeep: 6144:Gdp1In0igfUmKyIxLDXXoq9FJZCUmKyIxLX:GdpKn0V32XXf9Do3+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE647B06D1ED2E12CA41D67BD0C64DF6E7A602CA8ED4A59E370CB4BCAD67C323C76950
sha3_384: 0e0ebfe797e07682eb1828267bf948d0e94b3f8c7f8d7eb5b1a182b9969084ad2fc2ea49b7b8038d3959a4c9d899a9ee
ep_bytes: 90909090609090b800104000906a0490
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.102778
FireEyeGeneric.mg.d6934a7f9958c2f5
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Backdoor.fc
ALYacTrojan.GenericKDZ.102778
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.902455
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderTrojan.GenericKDZ.102778
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.90070a
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.iusgqk
RisingBackdoor.Berbew!8.115 (TFE:2:fIx4TDg4RLD)
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.102778
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.102778 (B)
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.dvpi
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.Generic.D1917A
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.GenericKDZ.102778
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!D6934A7F9958
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor!A5nRMmhQe3Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.A23B208121
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment