Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0D5A4727E56987F13A0B.mlw
path: /opt/CAPEv2/storage/binaries/786ca3b6f14021df45caa83b4e22ca721e0a6e3faa8235c86944d0d0b909c5de
crc32: C5436801
md5: 0d5a4727e56987f13a0bc24af0374189
sha1: fcb85f52717fd33927b8b7dc93be0ef53cdacccc
sha256: 786ca3b6f14021df45caa83b4e22ca721e0a6e3faa8235c86944d0d0b909c5de
sha512: 49cefd12be98eea2ea1bed69ad3a86d61ac41ecd42ec2076940209294386906e45e739e4476c1293a129b458321662bbffdf2a60dadb008817dbd8559365954e
ssdeep: 3072:UtnOuqpIu25beP203H/6TC+qF1SsB1bw4AVRrd9:UJ9qpO8P9C81NBy9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135C3AF7B37400FA2C5E412F0165E41CDF519F52AA5BB9654D0E4A03D373BAB463BBBA0
sha3_384: 3757a0899ac9caeebef8a500ae5cb89331de6bbee61ff7b44617fa1487527169c28d9a0d5b9f26ba14114ac7c64b5bac
ep_bytes: 9060b80010400090906a049090909090
timestamp: 2023-04-07 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.HangUp.5
MicroWorld-eScanGen:Trojan.ShellObject.h0Y@aGjJTmg
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOJ!0D5A4727E569
MalwarebytesPadodor.Backdoor.Bot.DDS
ZillyaTrojan.PadodorGen.Win32.21
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.bc2f3c5c
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.2717fd
ArcabitTrojan.ShellObject.EDEE5D
BitDefenderThetaAI:Packer.0C3353A21D
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.h0Y@aGjJTmg
NANO-AntivirusTrojan.Win32.GenKryptik.kcaixj
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.h0Y@aGjJTmg (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Trojan.ShellObject.h0Y@aGjJTmg
TrendMicroTROJ_GEN.R002C0DLE23
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.exyu
VaristW32/Pahador.QLFO-8537
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ViRobotTrojan.Win.Z.Padodor.122880.BIXZ
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.9FITS9
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLE23
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBNK!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment