Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C5488E9C5483B575E08F.mlw
path: /opt/CAPEv2/storage/binaries/b7e370a3696b13a4cb3c2a9e63126a0c53a137c1f660d4b6dac33c09a2f4dec2
crc32: B4171861
md5: c5488e9c5483b575e08f98e0476fdc2c
sha1: e95bd90b7fc8b49ae57c656b92c9a09a1d901b8b
sha256: b7e370a3696b13a4cb3c2a9e63126a0c53a137c1f660d4b6dac33c09a2f4dec2
sha512: 216bb9d46d877d9d51d6d2cf64880eb1181a8739ef45773880d323b67bb64a7ba8fa46c8cb9c664040fd6629b0862fa318996f9473c8484ef95f839f2ad50460
ssdeep: 3072:LVnEgudE9MyuenSJdEN0s4WE+3S9pui6yYPaI7DX:5EPdTSSENm+3Mpui6yYPaI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156D3C089279F2FFBD6E502B4204B14ADA329F57A933F876A446C818D12C2FF301B5579
sha3_384: 225d2ed5129c8dc28f198730d2703fba81d52f25ca0b8d3f5c7cdf4e9c9294a44f718715cf2ea491a2693efd279afac2
ep_bytes: 9090b800104000909090906a04909090
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.i8Z@ait5o7p
ClamAVWin.Trojan.Obfus-38
SkyhighBehavesLike.Win32.Generic.cc
McAfeeGenericRXHD-SL!C5466DEA7605
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.i8Z@ait5o7p
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.ED8C6F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.i8Z@ait5o7p
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
EmsisoftGen:Trojan.ShellObject.i8Z@ait5o7p (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.PadodorGen.Win32.7
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.eyag
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1G33IXO
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.AB6D347E21
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kg
YandexBackdoor.Padodor.AF
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.b7fc8b
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment