Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BD0A35FE8AEE13D96BE3.mlw
path: /opt/CAPEv2/storage/binaries/5370e71194170a98104f5014dde2354d44c847bdc80230c80a46925c84cb36f8
crc32: 249672E7
md5: bd0a35fe8aee13d96be361aa08e0fe95
sha1: 7191ca483a51013598e27c5acf07c6022be602e0
sha256: 5370e71194170a98104f5014dde2354d44c847bdc80230c80a46925c84cb36f8
sha512: 82073dac4b9b38ba45514c65440aa281329bcb9066bfaf46351088f67f9ec681209dcfbbe5423ec87f7d9ead5fb095b85e31b69f98a1a1309c853dfed39e1cb0
ssdeep: 3072:xdQuofDbhej5yslQEOeFKPD375lHzpa1P:fJofZeQslQEOeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14AA38E4FB29D2FF3C74102BC290E95E6FB1045380BABC19DB5FE843D55ABE25927A061
sha3_384: 01cf97a76ab7bbfa54ba1a92b6073981ccfa9aee4e99d512dac1b672314d235676f29aae527dcb24fb05a3da04e0b530
ep_bytes: 90909090906067e80000000058909090
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aOGzovi
ClamAVWin.Trojan.Crypted-31
CAT-QuickHealBackdoor.Padodor
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXPE-AP!44BA5748A6B4
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1893151
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.83a510
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aOGzovi
NANO-AntivirusTrojan.Win32.Padodor.kfuvcq
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.g8W@aOGzovi
TrendMicroTROJ_GEN.R03BC0DLO23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bd0a35fe8aee13d9
EmsisoftGen:Trojan.ShellObject.g8W@aOGzovi (B)
IkarusTrojan.Crypt
GDataWin32.Trojan.PSE.6Y5R0K
JiangminBackdoor.Padodor.erlj
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.EDD7AD
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGen:Trojan.ShellObject.g8W@aOGzovi
MAXmalware (ai score=82)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLO23
RisingBackdoor.Berbew!8.115 (TFE:2:ljEeaTdblGT)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.F2DCBEC921
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment