Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 989CEACD2CE2EFE87329.mlw
path: /opt/CAPEv2/storage/binaries/6bf66bebe5c2e4488817b84b096b63b5684f9955ccd2c2d91032e5ed8d7cd79c
crc32: DAEC60A1
md5: 989ceacd2ce2efe87329f2086055ca40
sha1: 5b9b971bc1d096b9523708360a63f232795303cf
sha256: 6bf66bebe5c2e4488817b84b096b63b5684f9955ccd2c2d91032e5ed8d7cd79c
sha512: be7f8b5e1cc6b838b0db690c4397adad704454f21c981286b8b410b2b495ea7fb70f47e5f87a310b64da56441d475052282686cd3aa3bdef785a5d76a5fb432e
ssdeep: 3072:13DdBWBbjUKC8fo3PXl9Z7S/yCsKh2EzZA/z:9doBcKCgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119B38EFFA3040F63CAD0C3BF158A4DB17609946833AE87518854805E1AD7E7C67BA9DB
sha3_384: 7f6ef9a50bcc141db2c895d1c3975b3287e461707407c9394bb3795d6b366423c93808c16fec3c433028357ccc6250ea
ep_bytes: 90909090b8001040009090bb38de4000
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aKrr!2b
FireEyeGeneric.mg.989ceacd2ce2efe8
SkyhighBehavesLike.Win32.Generic.ch
McAfeeGenericRXAA-AA!989CEACD2CE2
Cylanceunsafe
ZillyaTrojan.PadodorGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.f097a67a
K7GWTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.9F7E7E0821
VirITWin32.Padodor.V
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Packed.Barys-10002063-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aKrr!2b
NANO-AntivirusTrojan.Win32.Padodor.kfvbjg
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.hu
EmsisoftGen:Trojan.ShellObject.g8W@aKrr!2b (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
VIPREGen:Trojan.ShellObject.g8W@aKrr!2b
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Crypt
GDataGen:Trojan.ShellObject.g8W@aKrr!2b
JiangminBackdoor.Padodor.exyj
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.EF8CB9
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacGen:Trojan.ShellObject.g8W@aKrr!2b
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:sru23FZbUHP)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment