Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E00BFDD655FB8D2C3EC7.mlw
path: /opt/CAPEv2/storage/binaries/d8900719aee61e5d10e4afeccc582ab7e6921b096cfbb16067d5d472f2371fcc
crc32: 1B5C06C3
md5: e00bfdd655fb8d2c3ec7bf656774955f
sha1: 1727ddf3008005cd28b92d80f88faa38f282e825
sha256: d8900719aee61e5d10e4afeccc582ab7e6921b096cfbb16067d5d472f2371fcc
sha512: 3831418673a224dfbff9ce559b944ff484e4b36d73d80f44bec11229266ebbb78f0d000ba02f76ece1803dff5caf647b0d84f4f142b0c467700d092e7eac5e00
ssdeep: 3072:2U0VZshivccaDDM8c51WdTCn93OGey/ZhJakrPF:29VZjLUI8cCTCndOGeKTaG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153C34B5EB2963B31D28D03B2760FDDD2BB3AA13D066F8690646B825D13D3F6443B7189
sha3_384: 554d70ba17636e70a286e6f4de80b45277c8e09d35902cdfa4f1d2161feed0d9e9a8e96d8673b86ffabcda259c854e27
ep_bytes: 90906090909067e80000000058909090
timestamp: 1993-01-21 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.h8W@aCZnhbe
FireEyeGeneric.mg.e00bfdd655fb8d2c
SkyhighBehavesLike.Win32.Malware.ch
McAfeeGeneric Malware.bj
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusProxy-Program ( 003b8b111 )
K7GWProxy-Program ( 003b8b111 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.ED10DB
BitDefenderThetaAI:Packer.780C268C21
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.ivatbm
RisingBackdoor.Berbew!8.115 (TFE:2:Szh4PAsY7JG)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
ZillyaTrojan.Padodor.Win32.928092
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.egix
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.h8W@aCZnhbe
TACHYONBackdoor/W32.Padodor
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.300800
AvastWin32:Padodor-V [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment