Backdoor

Backdoor:Win32/Padodor.SK!MTB removal tips

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C7CE63990F8AF83D0F05.mlw
path: /opt/CAPEv2/storage/binaries/673eccf668fd0bd58b93685e9f61d39b5a3a7174b9d8ee77c8fec1871fd13aa0
crc32: 601A860B
md5: c7ce63990f8af83d0f05e4cff507e853
sha1: 162c9821a9c4638eb7af3d471648d031e191c00a
sha256: 673eccf668fd0bd58b93685e9f61d39b5a3a7174b9d8ee77c8fec1871fd13aa0
sha512: c9f8c3e7e8ab95c9e7a5c12faba14521af641b0b7386431bbdfca829d6cdd89373fb483c0b0aab5857087cc5e354615ec35da272cd28a92db17275b081169629
ssdeep: 3072:eZNs7NJBR7E6irpxMI5qrFTEEeFKPD375lHzpa1P:l7NJPABI5EEeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192A37C0FB7E13F62FB4407F72612A98AB21984345375F5E68B08173E213F6704679AE6
sha3_384: b0f4ee6d0af92a7d92be813a4d97a3e8d30f0de804a4f1d097fd77ccb27860dcac8e7269e0fbb28a5bb96df02722c30f
ep_bytes: 909090609090b80010400090bb38de40
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
MicroWorld-eScanTrojan.GenericKDZ.103285
ClamAVWin.Trojan.Crypted-29
FireEyeGeneric.mg.c7ce63990f8af83d
SkyhighBehavesLike.Win32.Dropper.nc
McAfeeTrojan-FVOJ!C7CE63990F8A
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Padodor.fcf2bea9
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.F2DCBEC921
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.kgtych
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
TrendMicroTROJ_GEN.R002C0DA924
SophosMal/Padodor-A
IkarusTrojan.Crypt
GDataWin32.Trojan.PSE.6Y5R0K
JiangminBackdoor.Padodor.denm
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitTrojan.Generic.D19375
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacTrojan.GenericKDZ.103285
MAXmalware (ai score=87)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DA924
RisingBackdoor.Berbew!8.115 (TFE:2:UcHyz6q6Y7K)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment