Backdoor

Backdoor:Win32/Padodor.SK!MTB removal guide

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 1ABE5B35B9FD6CC3D731.mlw
path: /opt/CAPEv2/storage/binaries/38537ce9554b021fafd1edf09ae2ec952ef96088c81310d0b5e3bb1dedf01c39
crc32: 365577F5
md5: 1abe5b35b9fd6cc3d7314d9dbd19d0fd
sha1: 46196a2f7411e84ad4f6a6df17a580b82b221d6e
sha256: 38537ce9554b021fafd1edf09ae2ec952ef96088c81310d0b5e3bb1dedf01c39
sha512: c55e02c65e312b51a93a497c60dcd339da0fd72893a755fcd5b1430a011577db3a6586849b6abaf402021d253016e8f1834aafc4634bc5e89ae1fdb59affbd36
ssdeep: 12288:TNKwJSLrpV6yYP4rbpV6yYPg058KpV6yYP8OThj:swJSLrW4XWleKW8OThj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T176B49C1659E72F25D911C1BC36134D9BBB5ACC262FEB8CD005FAC0CD912A674E2AB0F5
sha3_384: a90924a6fa8914f261f30902a36ce9def1a90464addb2d767806fae9f21d2cced1b72ddf2a9bb1b52792280e1eaf2f7b
ep_bytes: 90906090909067e80000000090909090
timestamp: 2021-11-23 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.EKZ@a8GaUlg
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.1abe5b35b9fd6cc3
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Backdoor.gc
ALYacGen:Trojan.ShellObject.EKZ@a8GaUlg
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.532505
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Padodor.2e2c279d
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.DAD0F4301D
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.EKZ@a8GaUlg
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.EKZ@a8GaUlg (B)
F-SecureTrojan.TR/Redcap.oufxg
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.EKZ@a8GaUlg
TrendMicroBKDR_BERBEW.SMA
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.bgkl
GoogleDetected
AviraTR/Redcap.oufxg
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.ShellObject.EA086E
ViRobotTrojan.Win.Z.Padodor.494126.OKJ
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.1D7CWH4
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXHD-SL!766B52A4065C
MAXmalware (ai score=86)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_BERBEW.SMA
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexTrojan.GenAsa!p1fO5hhCx5A
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.f7411e
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment