Backdoor

Backdoor:Win32/Padodor.SK!MTB removal

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E802DDBB46FD50205FE7.mlw
path: /opt/CAPEv2/storage/binaries/86f2d3b837f8f0b365df91a9f5d52f67a6b68140d5ac3b69bf79c14a79f371da
crc32: ABBD5D06
md5: e802ddbb46fd50205fe7d01e7bd14869
sha1: a14e76f88b5860ad7b94e29cb451892d319b076b
sha256: 86f2d3b837f8f0b365df91a9f5d52f67a6b68140d5ac3b69bf79c14a79f371da
sha512: 0b5fa540d205aa558ef441e9ad891a8733534e8e9f3a91b5df722555eabca36506f6c6d0f8e1bf4a3323f2855920e7c82bcf0a2d2f37fbef6015675df8691661
ssdeep: 1536:8cGBAYmTrcH4phnTbj9oNyia7cng3IxatrgfoxOlvKhduV9jojTIvjrH:8FB5mvZ79AyTcg3IxatrgfoxOYhd69j1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17CA38D47E1E62FD1DA70CFB5E20A6651F2567C3332AFB0B20010B44E251AA95E7FA747
sha3_384: af638789868d3f39c583dcfbc93978bead1d85a392cfab3d724255ff0e84a5816c03d61afa09b70ab2b921887f1191a3
ep_bytes: 90909090b8001040009090bb38de4000
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aiHu4Wp
FireEyeGeneric.mg.e802ddbb46fd5020
SkyhighBehavesLike.Win32.Generic.nc
ALYacGen:Trojan.ShellObject.g8W@aiHu4Wp
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g8W@aiHu4Wp
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.EC7E1E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Convagent-10013360-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aiHu4Wp
NANO-AntivirusTrojan.Win32.Padodor.jzpwdq
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.g8W@aiHu4Wp (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Convagent.fp
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.g8W@aiHu4Wp
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXPE-AP!E8E6ABF11621
MAXmalware (ai score=83)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:ostuCj5goYJ)
IkarusTrojan.Win32.Padodor
FortinetW32/Agent.B077!tr
BitDefenderThetaAI:Packer.911C0A761E
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.88b586
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment