Backdoor

Backdoor:Win32/Padodor.SK!MTB removal instruction

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BC1F07ABBABBFD287F87.mlw
path: /opt/CAPEv2/storage/binaries/7ddfa5b2fecd70a282443a4f0cb580e35a98330f29ee493cf199b02cd67b4034
crc32: 0F32DA9F
md5: bc1f07abbabbfd287f87473df36ff949
sha1: abcb683a6ae20fcef284f860afee8676a54ab173
sha256: 7ddfa5b2fecd70a282443a4f0cb580e35a98330f29ee493cf199b02cd67b4034
sha512: 077b73f5b58e0ab85ba0c7fc7efd34e892ec211a18307b2d48c7b265498b8f87c1e1e5724a8e97cebeab3d1d4411600cb8c77a3f8b0550b24a23333de71191bd
ssdeep: 1536:j2hANh4iMYU04pO1ZPnaBFC43/W94pDZudvgGNu/Ub0VkVNK:jbh4iMYUQPaB04ugu1gGNu/Ub0+NK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155937CDFBDC5AE83EE8535772014ADC2B11C5038D39D5D121B8C80AAD42EA798F79FA1
sha3_384: 0b61762e214aeed06aa06eb74eb774408e7eef5ea03921282686e94eb69007b117c8fa67064695f5f7b5f1df3d4134d2
ep_bytes: 90909090609067e80000000090909090
timestamp: 1984-11-04 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.fWW@aarXj5d
ClamAVWin.Trojan.Crypted-29
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOK!BC1F07ABBABB
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.fWW@aarXj5d
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a6ae20
ArcabitTrojan.ShellObject.E4D0C1
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.fWW@aarXj5d
NANO-AntivirusTrojan.Win32.Padodor.jypvmh
AvastWin32:Padodor-V [Trj]
RisingRansom.PornoAsset!8.6AA (TFE:2:KsanTfOGiFQ)
EmsisoftGen:Trojan.ShellObject.fWW@aarXj5d (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.713016
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bc1f07abbabbfd28
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.erlj
GoogleDetected
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.fWW@aarXj5d
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.60D6216921
ALYacGen:Trojan.ShellObject.fWW@aarXj5d
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-Proxy.Win32.Qukart.kj
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment