Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 769F01801AE75C320441.mlw
path: /opt/CAPEv2/storage/binaries/8ceaea7a07390ad01e6b42f2159ddb629fac9ac2f2bdd5e210f914a353dc9f31
crc32: 553BF9AE
md5: 769f01801ae75c320441a08f0c54b8bd
sha1: e231c6b728e6a4759435b808b7350fc2c76d1cf7
sha256: 8ceaea7a07390ad01e6b42f2159ddb629fac9ac2f2bdd5e210f914a353dc9f31
sha512: ccaa1451af168544748f6c2789eb2024e8f906a516e27a562466da6853a0083f13b39f11765283582c75b0e26a3490b50a349e0c25b2085776fd19d17c949e57
ssdeep: 3072:gIHWwb7V4ck9+BfKteXSJdEN0s4WE+3S9pui6yYPaI7DX:gIPbmX9+5KwiENm+3Mpui6yYPaI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9D3AE9BB11D9E26DB9602F0290798D6F369D1F0423A9CE095F8806D33477FC63F9299
sha3_384: 100d46e692ce292a33980319c277995eb5d275ebfcf0a1ca5709a2b3f99a3ab0fe8dc2f0e885666e665cd73c762b0162
ep_bytes: 909060909090b800104000909090906a
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.i8Z@aGN6KMb
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.769f01801ae75c32
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOJ!769F01801AE7
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.794085
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
ArcabitTrojan.ShellObject.E01D67
BitDefenderThetaAI:Packer.E277728A21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.i8Z@aGN6KMb
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kg
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.i8Z@aGN6KMb (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.i8Z@aGN6KMb
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.esac
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1G33IXO
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.i8Z@aGN6KMb
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusTrojan-Downloader.Win32.Berbew
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.728e6a
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment