Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 317A9A10F366E9C19687.mlw
path: /opt/CAPEv2/storage/binaries/6c3e3c00cfe3d8a72664aefde724d2ed838411512c2a168b489e8ab70e1bad60
crc32: 527D2DE6
md5: 317a9a10f366e9c196871db68fcff3d6
sha1: c18ba88d977761cd0536b02e4989446c1d6d21d8
sha256: 6c3e3c00cfe3d8a72664aefde724d2ed838411512c2a168b489e8ab70e1bad60
sha512: 27e178a2e0092ddf7b10dcf30206f4d1f9e6f77c0b7fb4d2f0b9c8e288f07d59fa52c1b52ec64b515696656fcbcd2abef69885f77f964440d9097af23eb3bd17
ssdeep: 6144:uF3bxYXssYL3/fc/UmKyIxLDXXoq9FJZCUmKyIxLjh:u1xrG32XXf9Do3i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3747C46D1EC6E33EA4AC67745C35DF2A6D242D987F4A48E360C84B86A879323CF7570
sha3_384: 04249322da2608407c00deb85fad1a7684994a98b5e8b60afcb197b9f67c66a1d3c1cd1c815324d6a9610a4e44c2ceed
ep_bytes: 60909090909090b80010400090bb38de
timestamp: 1977-12-31 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.103285
FireEyeGeneric.mg.317a9a10f366e9c1
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOJ!317A9A10F366
Cylanceunsafe
ZillyaTrojan.Padodor.Win32.470001
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.86165b6e
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.d97776
ArcabitTrojan.Generic.D19375
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.ivcmxt
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.103285
TrendMicroTROJ_GEN.R002C0DHD23
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Win32.Padodor
JiangminBackdoor.Padodor.dqkd
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.GenericKDZ.103285
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.E2DD51CF21
ALYacTrojan.GenericKDZ.103285
MAXmalware (ai score=83)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DHD23
RisingBackdoor.Berbew!8.115 (TFE:2:9yvesnxXv6N)
YandexBackdoor.Padodor!A5nRMmhQe3Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment