Backdoor

What is “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0D236ED03A343D0C508D.mlw
path: /opt/CAPEv2/storage/binaries/12fdad2b529ef20ece297baeeed408a5f1ac887befd7961dcdbd239b930a558a
crc32: B876CDC1
md5: 0d236ed03a343d0c508d225e89009328
sha1: 0a011b62fe095ad63ac1490433ba6860fa474cc5
sha256: 12fdad2b529ef20ece297baeeed408a5f1ac887befd7961dcdbd239b930a558a
sha512: e597c1c652b9c1fa3dda372aa36ecf1ded1eacd40c38583b469567df9b1871b9da62880f5259d04476970bc59eee474396214fcb660f473a030340f43236ae69
ssdeep: 3072:VI8/8PTvm/KiALtew5TZ5668fo3PXl9Z7S/yCsKh2EzZA/z:68/8iKR75v66go35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173B35ABFB6300F32C6C117B632C985E6762A8078D1A7EC9151A4C07E7ECAD69563F781
sha3_384: a8ed1618372012bd978bf09d5236916e3ca7a75891fd7cf60aa71392e4537db552b6f60b9af58a984ca3f593322fcc00
ep_bytes: 909090609090b8001040009090bb38de
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103285
FireEyeGeneric.mg.0d236ed03a343d0c
SkyhighBehavesLike.Win32.Generic.ch
McAfeeTrojan-FVOJ!0D236ED03A34
Cylanceunsafe
VIPRETrojan.GenericKDZ.103285
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D19375
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-29
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.ixaxhj
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.825730
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.103285 (B)
IkarusTrojan.Crypt
JiangminTrojanSpy.Qukart.ahio
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataTrojan.GenericKDZ.103285
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacTrojan.GenericKDZ.103285
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:2:UcHyz6q6Y7K)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
BitDefenderThetaAI:Packer.44E7344521
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.2fe095
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment