Backdoor

How to remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: DA63A4B1E168CC73210A.mlw
path: /opt/CAPEv2/storage/binaries/785dac62c78858149368e7e3ccfc85909e5f8986da269452e8631c24ab858b45
crc32: 1672CC07
md5: da63a4b1e168cc73210a856fb2857c36
sha1: 1be2be9645c6e1e19c920c1e45004f4e0962c3db
sha256: 785dac62c78858149368e7e3ccfc85909e5f8986da269452e8631c24ab858b45
sha512: 8c781cf68787d2fed169342f7d5acdc30f8948e576ccfa5b9afd2004dfc8e90f841e25e9691f0e31213dbeb3e93136fcf440673592d3ebe6922b151dd4d145a3
ssdeep: 3072:8z4mrqtQyfywZ7yVy4hqKhmB7rg85V8fo3PXl9Z7S/yCsKh2EzZA/z:8z4m4Q/V0AqKhaVgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136B38D1BF3B53FB3CBB10372319799D6FA1A8078F26ACC916895C0D8113A97D6376690
sha3_384: 053ac7a489b7db015f2295f52a951099589fc14f5b6186b830486669af52922c2579b896dc6cbe53ef1523162b12da9a
ep_bytes: 9090909067e800000000589090909090
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aKrr!2b
FireEyeGeneric.mg.da63a4b1e168cc73
SkyhighBehavesLike.Win32.Generic.cc
McAfeeGenericRXAA-AA!DA63A4B1E168
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.30130b33
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.645c6e
BitDefenderThetaAI:Packer.9F7E7E0821
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aKrr!2b
NANO-AntivirusTrojan.Win32.Padodor.jzbxuv
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.g8W@aKrr!2b (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
VIPREGen:Trojan.ShellObject.g8W@aKrr!2b
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
GDataGen:Trojan.ShellObject.g8W@aKrr!2b
JiangminBackdoor.Padodor.eyki
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.EF8CB9
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.g8W@aKrr!2b
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:sru23FZbUHP)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment