Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: B3DE7250BB8ECC924EA3.mlw
path: /opt/CAPEv2/storage/binaries/56503176d8e521af1fb727697a0aeeb9e3bff8cb3077c083362e48ce0515f4a4
crc32: 8B3ACFA4
md5: b3de7250bb8ecc924ea349a5296877ff
sha1: 852d24f948aa1021776cc01066d506d583ee8130
sha256: 56503176d8e521af1fb727697a0aeeb9e3bff8cb3077c083362e48ce0515f4a4
sha512: 12eec2cd180bf22c50160a89595caf2d4bc3eafc45a5a8d997e7bd25f0bfbc51c5349e4666ceec2744b2c3c0f635fbd5a009ebefca856b03c2fba51f4a426d8b
ssdeep: 1536:Cq0jH/Y25BBJfs47NiLmJfXzum5UG7FlicwePQmduV9jojTIvjrH:CqsfW47N+mJf55UG7FliwPQmd69jc0vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171A38C49F2601FE6F6FB03FD2A09C9AA7F02967467E9B4610064435F2EBFE254136342
sha3_384: dcab7ba3779317e62bde55cbb4ae45bdea370c2145ea4459c04c5c8e28bb4cbc01d9c3d20cabed95231b42d8883c257d
ep_bytes: 9090909067e800000000909090905890
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aiHu4Wp
FireEyeGeneric.mg.b3de7250bb8ecc92
SkyhighBehavesLike.Win32.Generic.nc
ALYacGen:Trojan.ShellObject.g8W@aiHu4Wp
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.15
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.948aa1
ArcabitTrojan.ShellObject.EC7E1E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Convagent-10013360-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aiHu4Wp
NANO-AntivirusTrojan.Win32.Padodor.ivyjws
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.g8W@aiHu4Wp
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.g8W@aiHu4Wp (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanProxy.Qukart.exl
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.g8W@aiHu4Wp
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
McAfeeGenericRXPE-AP!378759C6EBFC
MAXmalware (ai score=88)
VBA32Backdoor.Padodor
Cylanceunsafe
RisingBackdoor.Padodor!8.118 (TFE:5:ostuCj5goYJ)
IkarusTrojan.Win32.Padodor
FortinetW32/Agent.B077!tr
BitDefenderThetaAI:Packer.911C0A761E
AVGWin32:Padodor-V [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment