Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: CB42F5AEDE173BD1AD12.mlw
path: /opt/CAPEv2/storage/binaries/bff20aa913377a22814c4004ff50f9793d7b1a11229ada09b29c1c8bba9a937f
crc32: 33ED5D09
md5: cb42f5aede173bd1ad123761135f4bfb
sha1: 6db25b465019f22883c9e27a92b6e2ba8f9edf68
sha256: bff20aa913377a22814c4004ff50f9793d7b1a11229ada09b29c1c8bba9a937f
sha512: fabc48b44efca173c0cb2d1db659da7b151312af7d9ecce81da80484398e3d04cff5153e13f8b5bfcab077dcd5580125fd6a9fdd1965251e3e91f18fe82a98c3
ssdeep: 3072:mDPNsHJ4cULsElnc2mDQjdSCSKoK08uFafmHURHAVgnvedh6DRyU:yPNEmsUncRDQjQCSKoK08uF8YU8gnves
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8F34C2B7248CF72DF8302F6360B57FAB629B9773E7685A15479805D1346E2C927A2C0
sha3_384: a6dff53daa4d5b6ed53b5cd5c6ed736860edd449f3cc19c1eefef082e496abcde415fcc3268fbb465355220d2fda5d84
ep_bytes: 60909090909067e80000000090589090
timestamp: 1979-05-15 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.k8Z@au4JtZd
SkyhighBehavesLike.Win32.Generic.ch
McAfeeTrojan-FVOK!CB42F5AEDE17
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.972323
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.65019f
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.k8Z@au4JtZd
NANO-AntivirusTrojan.Win32.Padodor.kbmexj
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.k8Z@au4JtZd (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.k8Z@au4JtZd
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.erlj
VaristW32/Backdoor.DKIC-2994
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.ShellObject.ECEB67
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.k8Z@au4JtZd
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.9B09EDDD21
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:3:z72GK0tGysF)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment