Backdoor

Backdoor:Win32/Padodor.SK!MTB removal

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 39A38542E7BB66F47311.mlw
path: /opt/CAPEv2/storage/binaries/98ec672ad0bfc52b64e2f77caa094d8c9eca594cd35399700f58f0efa76febf4
crc32: 4DB2FC2B
md5: 39a38542e7bb66f47311299a308363bc
sha1: d35a22f0bfce642a2a73a3adb990ca30cda6f6f1
sha256: 98ec672ad0bfc52b64e2f77caa094d8c9eca594cd35399700f58f0efa76febf4
sha512: 7ab8f2f321b537d55171ddef5261e70fdbe9af2943967f909a01fae899c3aa72d0c0dba2b639e10d72ec03a840355c9c499b677d0d1b072cc62cf1ec0ba8669a
ssdeep: 3072:nniY9ouTf7Dza8QPY34pTwmxvPxMeEvPOdgujv6NLPfFFrKP92f65Ha:iyouPq8QPgmxvJML3OdgawrFZKPf9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185043A1BB3492F71FAA10375370BDDE6A71A8078337949AC14788C1E2663F6C817B6B5
sha3_384: 4c43980dc4ab161912b5fb1ae4656fc8730c59f662c19e7d99c26e5bd85f5fdcef8c13b19c396032d55680aa1915e7d0
ep_bytes: 90906067e80000000090909058909005
timestamp: 1983-06-23 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXPE-AP!52D1E736911C
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.26
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.E31BED
BitDefenderThetaAI:Packer.222A852021
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Packed.Zpack-10001780-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.k8Z@aC9JiEk
MicroWorld-eScanGen:Trojan.ShellObject.k8Z@aC9JiEk
AvastWin32:Padodor-V [Trj]
RisingBackdoor.Berbew!8.115 (TFE:5:QsDMY84vnqT)
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.k8Z@aC9JiEk (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPREGen:Trojan.ShellObject.k8Z@aC9JiEk
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.39a38542e7bb66f4
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.eyfj
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.855VXQ
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.k8Z@aC9JiEk
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.0bfce6
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment