Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 02AE15A7E692D083AB21.mlw
path: /opt/CAPEv2/storage/binaries/f9f63c60dc9803afc346eb6ba391c50b181058995da3239a582de86d895d0b52
crc32: 589F52C1
md5: 02ae15a7e692d083ab210836aab8042d
sha1: 8f8ff362ef70cb7b32e3d367361b84ec8de32b50
sha256: f9f63c60dc9803afc346eb6ba391c50b181058995da3239a582de86d895d0b52
sha512: ddaa3e81415e34330e2714bfdc17f4be4772e3bb9ce5a68fcfe724c6ae3b5c34aa8212259a7ff65e62121ff8f7912dc64b287ce3fc245f9d64e84eb4f43c2ebf
ssdeep: 1536:u5/+cotBYcUJvPS3FqFsYvD70mCjn7eCRMkrmMx5BkduV9jojTIvjrH:ol5cqvPSVqF9DYmCjiLUdBkd69jc0vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14FA36BDBE2583FF5C785007F3B1682ABE32180EA5A6D8491AD1CD3DE7D1FE1485A4B90
sha3_384: 7a7bfe6b77e534e8dcbb407e2464892d7e54440d970e09354adffe1dd912afc32c548282ca7005e34979200784b47f29
ep_bytes: 9090909067e800000000909090589090
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aiHu4Wp
ClamAVWin.Malware.Convagent-10013360-0
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXPE-AP!6A6241320AF8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.15
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.2ef70c
ArcabitTrojan.ShellObject.EC7E1E
BitDefenderThetaAI:Packer.911C0A761E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aiHu4Wp
NANO-AntivirusTrojan.Win32.Padodor.iusybz
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.g8W@aiHu4Wp (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPREGen:Trojan.ShellObject.g8W@aiHu4Wp
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.sws
GoogleDetected
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.g8W@aiHu4Wp
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:ostuCj5goYJ)
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment