Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0C927AA6F4CAC7393C6D.mlw
path: /opt/CAPEv2/storage/binaries/555d4d292ba903d96571ff971fe03525fe656ef1286e3ca8e58d24dc709223c5
crc32: E922526A
md5: 0c927aa6f4cac7393c6d35c921976ae9
sha1: 9dc5762e8d09350eb60d469bc3e0c0c04f5c2d3e
sha256: 555d4d292ba903d96571ff971fe03525fe656ef1286e3ca8e58d24dc709223c5
sha512: 20845f724f2cc1fc78d9335f22e1add1519d1f94347ed330abd08a65036e58c186d0da078cd14f61c72c7756423d417be594f53bf92b0987ad1784c456f170a7
ssdeep: 1536:cS1tsPwP+ObLHnxwn/B6RH4guGmboN5w31fLD//fUYJmXxfOOQ/4BrGTI5Yxj:cS1N+MLi5SJmboN5w5X/4RU/4kT0Yxj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C993AF4BA628DF76E9434334B3C79C039B248774437DC3E8DBD8E4D82252D59A2BA6D1
sha3_384: 6c2ea12a2ceb87a994f40a2351a2eff2fa207b3d5a63827e5650c0c32b986b37dd8d540b0078b72a5a59cf2cb353cd7a
ep_bytes: 9067e800000000905890909090900563
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.f0W@aSlVvue
SkyhighBehavesLike.Win32.Generic.nc
McAfeeArtemis!0C927AA6F4CA
Cylanceunsafe
ZillyaTrojan.Padodor.Win32.2160685
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.8d357ecd
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.ShellObject.E0D2C7
BitDefenderThetaAI:Packer.C9D93E8421
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.f0W@aSlVvue
NANO-AntivirusTrojan.Win32.Padodor.kfatdb
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.km
EmsisoftGen:Trojan.ShellObject.f0W@aSlVvue (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
VIPREGen:Trojan.ShellObject.f0W@aSlVvue
TrendMicroTROJ_GEN.R03BC0DL723
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.exys
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ViRobotTrojan.Win.Z.Padodor.92672.XMS
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.f0W@aSlVvue
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DL723
RisingBackdoor.Padodor!8.118 (TFE:5:ANhzeVHq5GO)
YandexBackdoor.Padodor!UU29uXlI7KA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.e8d093
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment