Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: DE32C484EE04BD232C50.mlw
path: /opt/CAPEv2/storage/binaries/c9e68342640915cad6eef3f9602ed4e21a7bd9330336fdc2f5897fade54f61a1
crc32: 7F17DCDA
md5: de32c484ee04bd232c504c881efcdda9
sha1: 78c984370f6eac784c7dd459df2ff9914cbcdf55
sha256: c9e68342640915cad6eef3f9602ed4e21a7bd9330336fdc2f5897fade54f61a1
sha512: 1e7a9d1851d1776444fc9d33f713fd0f4bc0fff59358e0a60d636301f2a6d7c2761e8006e93368c01b3aac84d0a00e9467a79f4a617be2b5ae0b156f775911c4
ssdeep: 3072:q2a+Z/XvaTB/NlobuLvkHHvvvn8CDVkTQHE4eFKPD375lHzpa1P:dRZad1+YsHHvvvn8CDVk0E4eYr75lHze
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FA38C1BB81B0F71C39E05BE350916C2F12FD53983ACD3B2541882B99F9B658116ADFD
sha3_384: e856757bbde13ed9ba98164f3c79b5fd5675063eee38698052593d067db5a3609dc78af4249c54e8977d364c92c1f8d7
ep_bytes: 9090b8001040009090906a0490909090
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.4!c
MicroWorld-eScanTrojan.GenericKDZ.102778
FireEyeGeneric.mg.de32c484ee04bd23
SkyhighBehavesLike.Win32.Generic.nc
ALYacTrojan.GenericKDZ.102778
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.102778
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.102778
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaGen:NN.ZexaF.36792.g8W@aiKV3eh
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.EZNP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyUDS:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Padodor.cc848d2e
NANO-AntivirusTrojan.Win32.Qukart.jzcfar
ViRobotTrojan.Win.Z.Padodor.100864.BQMV
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.HangUp.44049
TrendMicroTROJ_GEN.R03BC0DK623
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.102778 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.eybj
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Backdoor]/Win32.Padodor
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.Generic.D1917A
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.6Y5R0K
VaristW32/Agent.FTJ.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXVP-YB!F43FFD718A3A
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DK623
TencentBackdoor.Win32.Padodor.kl
IkarusTrojan.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
Cybereasonmalicious.70f6ea
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment