Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: BBFCFF7E734FD47B85B9.mlw
path: /opt/CAPEv2/storage/binaries/1e2d8cd61aff94a988185748c502610640e247920a32d2d4ee1f221540a387d3
crc32: C0BC4FD2
md5: bbfcff7e734fd47b85b9abdf6a1b2954
sha1: 92ecff435ec35e7ae82fd3c25407686ab6218cb8
sha256: 1e2d8cd61aff94a988185748c502610640e247920a32d2d4ee1f221540a387d3
sha512: eac3b390cfd46d4ee9ce0b8929ff181f0ed2252b14708e7f09a7d0e5ee844f531a7813f34804fa02618dd955e3529860d1545258a91d3b5c0f78e64b1db80a7f
ssdeep: 3072:E7Wv2mURF9oa2E9JmDqe4QQO7AJnD5tvv:J2mURF9gEPm5FQOarvv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11FC36B5BB7495F72C78202B22F0A54C6B71DC23412FAC6A15498C05D2327F2B76BE6DE
sha3_384: 7346ec8c19119acd6b89520071bdaaaeb0539e890323f6e7a906a9fc80e7f4a36de945634026c97601d9a4625945d079
ep_bytes: 90609090909090b800104000bb38de40
timestamp: 1982-02-08 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103285
SkyhighBehavesLike.Win32.Generic.ch
McAfeeTrojan-FVOJ!BBFCFF7E734F
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.22
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.6c24d2e5
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.35ec35
ArcabitTrojan.Generic.D19375
BitDefenderThetaAI:Packer.129D9E5E21
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.jzykiw
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftTrojan.GenericKDZ.103285 (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.103285
TrendMicroTROJ_GEN.R03BC0DL623
SophosMal/Padodor-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.erlj
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.J9SS1X
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DL623
RisingRansom.PornoAsset!8.6AA (TFE:2:1QjD8ksFU9R)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment