Backdoor

What is “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: DE4C28611D408203DF7E.mlw
path: /opt/CAPEv2/storage/binaries/c56c31fbc0007a510bc090faf3c3ba10fab743f21262a4d224b7cacc3ba3566b
crc32: 388F8E25
md5: de4c28611d408203df7e7fb85e20682a
sha1: abd3b3f527af60fc3620b9e2268ac1d1afa55dfe
sha256: c56c31fbc0007a510bc090faf3c3ba10fab743f21262a4d224b7cacc3ba3566b
sha512: 4e0972924f971998f91c1452704ff0dab43977c7a57f7c3384f970c88e84b15fef72fc97e45f0ec68526a870893775b0fe184d69450df4fa1ead0c6f38e491bc
ssdeep: 3072:9M26zErgyv4c9vE5cJnbVOuox8fo3PXl9Z7S/yCsKh2EzZA/z:9R6zX039vRJZOuoxgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138B37DBBB2451FB6C29342B2750695E1773B9C3802B985504EACC35D1212E6CDFBEADC
sha3_384: ef23da5dc3b794017c7342042839c64d095b5248810b3ea8a2eec3dc4255fd57624afdfc3d43eab634c75aaba8a109e4
ep_bytes: 90909060b80010400090906a04909090
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
AVGWin32:Padodor-V [Trj]
tehtrisGeneric.Malware
DrWebBackDoor.Wdozer
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aKrr!2b
SkyhighBehavesLike.Win32.Generic.cc
McAfeeTrojan-FVOJ!DE4C28611D40
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.11d408
BitDefenderThetaAI:Packer.9F7E7E0821
VirITWin32.Padodor.V
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Padodor-V [Trj]
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aKrr!2b
NANO-AntivirusTrojan.Win32.GenKryptik.kcaixj
RisingBackdoor.Padodor!8.118 (TFE:5:sru23FZbUHP)
EmsisoftGen:Trojan.ShellObject.g8W@aKrr!2b (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
VIPREGen:Trojan.ShellObject.g8W@aKrr!2b
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.de4c28611d408203
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.CRA1EH
JiangminBackdoor.Padodor.eydk
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitTrojan.ShellObject.EF8CB9
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.g8W@aKrr!2b
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
IkarusTrojan.Crypt
FortinetW32/Qukart.A!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment