Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: B7522244F382B392FD88.mlw
path: /opt/CAPEv2/storage/binaries/2c4fe1f1e371c12afc73c6e1baa86e93f34ae43c4c4c58362ec073a4fd260227
crc32: FD06D468
md5: b7522244f382b392fd88980fe677ed7c
sha1: 7fa63694452c3b5d57adf863f15288790abd943c
sha256: 2c4fe1f1e371c12afc73c6e1baa86e93f34ae43c4c4c58362ec073a4fd260227
sha512: 8c678d7850433b43d7be39473db9ce6c009453b8e1ca2300a5c97a4287b0fbb4706f8fe3547bd9ecadffacf91666d88262907a4bc48079e6937ba3dfd7198a4a
ssdeep: 3072:davLDZqSbxwJEOy16rEyeFKPD375lHzpa1P:0ISbxwJEUrEyeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7A39D17F2122F30FE5D05F3B6076486B714A92853ABCDB61DF4D0ADD21A91882BF6D2
sha3_384: 11d94a6c84c93ab441a31d7d2b958cf5811018a43095cd2b5a051460c1405ad95fc720d91c59609dfca9084943c5529c
ep_bytes: 9060909067e800000000909090589090
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
MicroWorld-eScanGen:Trojan.ShellObject.g8W@a4IIY9p
FireEyeGeneric.mg.b7522244f382b392
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOK!B7522244F382
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g8W@a4IIY9p
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.7b779354
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.4452c3
ArcabitTrojan.ShellObject.E7C454
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Padodor-10013598-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@a4IIY9p
NANO-AntivirusTrojan.Win32.Padodor.iwfdkj
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.g8W@a4IIY9p (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
TrendMicroTROJ_GEN.R03BC0DLN23
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.exyg
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.2FD6A0E321
ALYacGen:Trojan.ShellObject.g8W@a4IIY9p
MAXmalware (ai score=86)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLN23
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment