Backdoor

Backdoor:Win32/Padodor.SK!MTB removal

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: B2FB80376A07E60FAFB6.mlw
path: /opt/CAPEv2/storage/binaries/424409a4bad1009fa67d3c19a5de01e1258d6f4f95f274b6d8eddefedf7ab132
crc32: D1091B51
md5: b2fb80376a07e60fafb604fea2ae65ac
sha1: 7f4b99e734cc4e41c72742f389dc99592a7a4da1
sha256: 424409a4bad1009fa67d3c19a5de01e1258d6f4f95f274b6d8eddefedf7ab132
sha512: b8e6e168fef4db3b43a31750df6b110f72a3d9659bf77e4d3ac96bcc81e6a0472a382c9cd7eeab28a6dc723b18104136941a036b01bf4d1766fd13137c651a66
ssdeep: 6144:wF7EisPut3/fc/UmKyIxLDXXoq9FJZCUmKyIxLjh:wwisP332XXf9Do3i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188748D06D1ED6E13CAC6E67B45D20DF6AAA602D982E4A4DE370CCCB47E568313CF1D94
sha3_384: 6f4907ec207184ff6954f8c06a49a576b10be808889a01099fd60b57080bbd0deee2a0535d90bd86cf4ceacf68eef00e
ep_bytes: 90609090909067e80000000090909058
timestamp: 1977-12-31 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.GenericKDZ.103285
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOK!B2FB80376A07
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Trojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Trojan.GenericKDZ.103285
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.734cc4
BitDefenderThetaAI:Packer.E2DD51CF21
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.iuuecz
RisingBackdoor.Berbew!8.115 (TFE:2:OZNHsQD3f1G)
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.1008856
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b2fb80376a07e60f
EmsisoftGenPack:Trojan.GenericKDZ.103285 (B)
IkarusTrojan.Win32.Padodor
JiangminBackdoor.Padodor.ctvg
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Generic.D19375
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGenPack:Trojan.GenericKDZ.103285
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGenPack:Trojan.GenericKDZ.103285
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
YandexBackdoor.Padodor!A5nRMmhQe3Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment