Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: A3B85F80FEE3C4532DE8.mlw
path: /opt/CAPEv2/storage/binaries/5c2591dcaaada12f94f6d9791c1c53a0121431c304d5806f63fe5b6b768ac7e5
crc32: 39C8818D
md5: a3b85f80fee3c4532de85aed0e13f09a
sha1: 410040cebf9392efcc256e947b5fd35ddc367921
sha256: 5c2591dcaaada12f94f6d9791c1c53a0121431c304d5806f63fe5b6b768ac7e5
sha512: fe29c8d1b6b1fc6cd4f56dbfa88924821f99ef08e14b28c52d86135bb38385ca17b42b7d67db336d560a4bd11edbc645fa5f082b66921ee586b51e70ad71687b
ssdeep: 3072:7lUTl2fI0lz/DLHEVeFKPD375lHzpa1P:7lUTl4Xl3LHEVeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189A37BFBB6470F6DC7F513711E3A4BD2F32D143E22E5A9D9845CB04A22AB679027A341
sha3_384: 40ee2d4ac6872d364ca9526b72eb42b6358aa57ae5e127672cd7721bbf3cf8981683a2b70e04400523fd87a4e2bdd170
ep_bytes: 90909090906067e80000000090905890
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aOGzovi
ClamAVWin.Trojan.Crypted-31
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXPE-AP!600CF9084743
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g8W@aOGzovi
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGen:Trojan.ShellObject.g8W@aOGzovi
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.ivlwnt
AvastWin32:Padodor-V [Trj]
RisingBackdoor.Berbew!8.115 (TFE:2:xj4tAqEbGWH)
EmsisoftGen:Trojan.ShellObject.g8W@aOGzovi (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
SophosMal/Padodor-A
IkarusTrojan.Crypt
GDataWin32.Trojan.PSE.6Y5R0K
JiangminBackdoor.Padodor.ecng
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.EDD7AD
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.F2DCBEC921
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.ebf939
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment