Backdoor

Backdoor:Win32/Padodor.SK!MTB removal tips

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: D6F0B2E6D2883C31428B.mlw
path: /opt/CAPEv2/storage/binaries/490584e6f79322bff63b33a28d4c1cc9956a04f07bf77201c1d8d1720b2785b0
crc32: 78F3DE77
md5: d6f0b2e6d2883c31428b8e5656735ab8
sha1: 3f75b64fe810151fb82a8c0cf96e2cece6506686
sha256: 490584e6f79322bff63b33a28d4c1cc9956a04f07bf77201c1d8d1720b2785b0
sha512: d146ced2c1bc098efa8dd649cbad517da52d77242c2a7990b2882f8d33a1b59fd27cddf78eedd95cc5a646425d0244f4b9829e3424ede31d24376a9286dab8a7
ssdeep: 3072:zbgsYVT96gXu5NC0vcC1WdTCn93OGey/ZhJakrPF:QsYfbXu50QcxTCndOGeKTaG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145C35B2BB7450FB6C38107B2263B9BC7F72A5DB912ED84A0345C805D264BE7C577BA81
sha3_384: e1d0d753b2df7a9c3789a905e38b2e4553c2f886f1d559fe02c33f3f6294e86a8be40081a8b5b56ee03548ed19099774
ep_bytes: 60909090909067e80000000090905890
timestamp: 1993-01-21 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.h8W@aCZnhbe
FireEyeGeneric.mg.d6f0b2e6d2883c31
SkyhighBehavesLike.Win32.Malware.ch
McAfeeTrojan-FVOK!D6F0B2E6D288
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.23
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITWin32.Padodor.V
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-36
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.h8W@aCZnhbe
NANO-AntivirusTrojan.Win32.Padodor.kbihiv
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
GoogleDetected
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.h8W@aCZnhbe
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.h8W@aCZnhbe (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15MS2TX
JiangminTrojanProxy.Qukart.fez
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.ED10DB
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.780C268C21
ALYacGen:Trojan.ShellObject.h8W@aCZnhbe
MAXmalware (ai score=87)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:3:USKdqYk7ZtS)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.6d2883
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Berbew.e6a9a0e6

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment