Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: DBD32F4CFE8C10B9886D.mlw
path: /opt/CAPEv2/storage/binaries/66e33c5f0946b8b7d7cbdf234dcceacd1ec606316eaa60d714361d6235800cc1
crc32: 7B3AA36B
md5: dbd32f4cfe8c10b9886dcfb56c59eed5
sha1: a0669ac45b415b779c680af3c9d6b21731fd48ee
sha256: 66e33c5f0946b8b7d7cbdf234dcceacd1ec606316eaa60d714361d6235800cc1
sha512: b1286494678f4744bd7bdae8752a9faa3467caeb34141bc8568a1284becc7fde394f562f535dd4d72c5b88ae1d29fa4aa659c05c9de3f5002c264316ccdc2175
ssdeep: 3072:Dstn3uXylPEOVjOgaVySPs5dOlqnBc31WdTCn93OGey/ZhJakrPF:I5PrVjpa4QlqBcITCndOGeKTaG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6C35C7BB7452F32CA9202FD36075AD6FA268035F369DFD05C98801EE257F38427A694
sha3_384: 950ec9eee77f93bc6c27377f51462915feb920e7111adc273334caaf17889ce3fa209950ba4ea334cab24cfc2410b90c
ep_bytes: 90909090906067e80000000090905890
timestamp: 1993-01-21 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.304514EE.A.5BF19C01
FireEyeGeneric.mg.dbd32f4cfe8c10b9
SkyhighBehavesLike.Win32.Malware.ch
McAfeeGeneric Malware.bj
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.45b415
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGeneric.Dacic.304514EE.A.5BF19C01
NANO-AntivirusTrojan.Win32.Padodor.ivvcrr
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGeneric.Dacic.304514EE.A.5BF19C01 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
VIPREGeneric.Dacic.304514EE.A.5BF19C01
Trapminemalicious.high.ml.score
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.erlx
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGeneric.Dacic.304514EE.A.5BF19C01
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.15MS2TX
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGeneric.Dacic.304514EE.A.5BF19C01
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:2:xj4tAqEbGWH)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.780C268C21
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment