Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: B5F7E4DCD606B9C34527.mlw
path: /opt/CAPEv2/storage/binaries/eebd121f55b4b515d8d56d8275d3d6377f6e69e544a373950baa4f31bd097151
crc32: B35B8BC7
md5: b5f7e4dcd606b9c34527c2771888171c
sha1: b623df01bc6b9e104cc267a66452eb8bb67548f7
sha256: eebd121f55b4b515d8d56d8275d3d6377f6e69e544a373950baa4f31bd097151
sha512: 1f0abd2835ec2dfd9ab90489962868dc569921f76667ceda456fad837b6f4981885881faf40ec4c898c9d312f2f119065524eab22f45799a36c037d7db5831c0
ssdeep: 3072:fdjdBpJTnwRqOwR4GIh8fo3PXl9Z7S/yCsKh2EzZA/z:fVN1nwRqOwChgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148B37D6BF2150FBAC7D101B32A0F84DE7B3B846593A7C5605598F04D9327EEB03BA664
sha3_384: e3e87de33020fda1f29255903a962d6f1e9cb82010a8919830db258c006667c764a70bce18f1ca21993d2d0280bb4192
ep_bytes: 90906090909067e80000000090909090
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.AB13442E.A.F6C18A45
FireEyeGeneric.mg.b5f7e4dcd606b9c3
SkyhighBehavesLike.Win32.Generic.cc
ALYacGeneric.Dacic.AB13442E.A.F6C18A45
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.AB13442E.A.F6C18A45
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGeneric.Dacic.AB13442E.A.F6C18A45
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.jwxwyi
RisingBackdoor.Berbew!8.115 (TFE:3:zpmVsI3EQDM)
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.AB13442E.A.F6C18A45 (B)
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.etpf
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGeneric.Dacic.AB13442E.A.F6C18A45
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGeneric.Dacic.AB13442E.A.F6C18A45
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOK!B5F7E4DCD606
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.44E7344521
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.1bc6b9
AvastWin32:Padodor-V [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment