Backdoor

Backdoor:Win32/Padodor.SK!MTB removal

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 96CFEB8550670BD6162E.mlw
path: /opt/CAPEv2/storage/binaries/dfeb9a9a5a98fb1b3efde950bdb99022ed7f1e5be97ab44cc6fbc31f4405fd58
crc32: 8249E3DF
md5: 96cfeb8550670bd6162e6ce1b8a9ce97
sha1: e03d948f86abff0d2da4eaa8d9937fc309cab2c9
sha256: dfeb9a9a5a98fb1b3efde950bdb99022ed7f1e5be97ab44cc6fbc31f4405fd58
sha512: ad5bddd2a6382bd8ed95358587d7e4ade8abe092e7da54d38d60582221ae90d69997ab3b53b572f320c59077376ecc3e82bc1a8a22f9282a0dee470618e1ec3a
ssdeep: 3072:dx2lXxXvMJMe+75bLkLrOmPE2EKeFKPD375lHzpa1P:dOvMJhcyrfE2EKeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5A38C1EF6181EF3CA4300BD120B459BBA15B92A51FBC0B680DCCB5E114796D73BA6DE
sha3_384: 9ae30ab5b08bc5b04b8687f18ef1856917c22672aa61c4b4370a07b20960915892947236618caf43e15ccfe4eed154f7
ep_bytes: 9090909067e800000000909090909058
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Obfus-38
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXPE-AP!4F421C6FEC41
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g8W@a4IIY9p
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGen:Trojan.ShellObject.g8W@a4IIY9p
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.f86abf
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
NANO-AntivirusTrojan.Win32.Padodor.jvtokc
MicroWorld-eScanGen:Trojan.ShellObject.g8W@a4IIY9p
AvastWin32:Padodor-V [Trj]
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
EmsisoftGen:Trojan.ShellObject.g8W@a4IIY9p (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
SophosML/PE-A
IkarusTrojan.Crypt
GDataWin32.Trojan.PSE.6Y5R0K
JiangminBackdoor.Padodor.exyg
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.E7C454
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
BitDefenderThetaAI:Packer.2FD6A0E321
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment