Backdoor

Backdoor:Win32/Padodor.SK!MTB information

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C376BF500BF5C5E1E90F.mlw
path: /opt/CAPEv2/storage/binaries/d83323df7c4928d8eaea0e326fd157ffbf4e63f7f361e45e15d8735030d46242
crc32: 78431234
md5: c376bf500bf5c5e1e90fd85d23a52eaa
sha1: 4b2f3a64477b5e85c3765ff77b1d0649d38290d4
sha256: d83323df7c4928d8eaea0e326fd157ffbf4e63f7f361e45e15d8735030d46242
sha512: 347d20efbbd89e4b4c9da3653dce1cd43652c1730feecdd57148ee918e5f3a2240d396a8e0446d5165c3b993e42dac630a6b67891f937389e5ba75e1923ddf72
ssdeep: 3072:0maH81RfGynxhOvyiLEreFKPD375lHzpa1P:7nRVx6TEreYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108A39E7FA2871FA1C6EE04712A0F618DFBE6D62411E9D2B50A1CD8590123D689FF728D
sha3_384: 250bc0d6ac4deb104faa6787a1908557ccf9123dc5578bc271d889e22ff46334d22482731e464aeafbf5b5743faf9913
ep_bytes: 60909090909067e80000000090905890
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGenPack:Trojan.GenericKDZ.103285
FireEyeGeneric.mg.c376bf500bf5c5e1
SkyhighBehavesLike.Win32.Generic.nh
ALYacGenPack:Trojan.GenericKDZ.103285
Cylanceunsafe
VIPREGenPack:Trojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGenPack:Trojan.GenericKDZ.103285
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.4477b5
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-36
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.kbmkqx
RisingBackdoor.Berbew!8.115 (TFE:3:QiBb7Shd7yJ)
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.1338992
Trapminemalicious.high.ml.score
EmsisoftGenPack:Trojan.GenericKDZ.103285 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
JiangminBackdoor.Padodor.erlj
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGenPack:Trojan.Generic.D19375
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOK!C376BF500BF5
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kl
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.F2DCBEC921
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment