Backdoor

Backdoor:Win32/Padodor.SK!MTB removal tips

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0A516F0050C4F1145BF5.mlw
path: /opt/CAPEv2/storage/binaries/09459106adbcff1408ba9ac3aabf0149e9a3e2caf4f7884138e9593a34a46d38
crc32: E13A05A5
md5: 0a516f0050c4f1145bf5663259eb26c6
sha1: b74b2400aec34f104eef5c56b61ebc231d803ae7
sha256: 09459106adbcff1408ba9ac3aabf0149e9a3e2caf4f7884138e9593a34a46d38
sha512: 66f6aead16a7aa7715f33b722e2df4ba0a139204d7a9fe0e4d76d22eb4f5979cdbadd2bb82202f0116ef1166830fc416885be698ab4841ffb6e0ca6010bcef70
ssdeep: 6144:NVPYHofSTe2XfxqySSKpRmSKeTk7eT5ABrnL8MdYg:4HofSTN5IKrEAlnLAg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D346C1AAF047F72C78182F1163E59DAF6148C6743A592D32D17A0CD120AFFD62BEAD1
sha3_384: fe3ff882c875523fa448fd4bc1edd806f4810a27a706ed4e5594b39da56f6702dc6093318e89c95f64d9ff1fea8da265
ep_bytes: 90906090909067e80000000090909090
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebBackDoor.Wdozer
MicroWorld-eScanTrojan.GenericKDZ.102778
FireEyeGeneric.mg.0a516f0050c4f114
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.dh
ALYacTrojan.GenericKDZ.102778
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.102778
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderTrojan.GenericKDZ.102778
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.0AA2894B1E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.ixmrvo
RisingBackdoor.Padodor!8.118 (TFE:5:fGiz2IHxOJD)
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Crypt.XDR.Gen
ZillyaTrojan.QukartGen.Win32.1
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.102778 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
JiangminBackdoor.Padodor.erlj
GoogleDetected
AviraTR/Crypt.XDR.Gen
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.Generic.D1917A
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.FNZL9N
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.0aec34
AvastWin32:Padodor-V [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment