Backdoor

Backdoor:Win32/Padodor.SK!MTB malicious file

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 9F7F4535163F091367FE.mlw
path: /opt/CAPEv2/storage/binaries/038d6955316d713c2cbf4e93315fc1093d7bb3fb915b85bb6caa90188d3bbfa5
crc32: AE6239F0
md5: 9f7f4535163f091367fe19db66b936a0
sha1: f22df45064ccf2bce65e3d4b92c43495201706aa
sha256: 038d6955316d713c2cbf4e93315fc1093d7bb3fb915b85bb6caa90188d3bbfa5
sha512: f2297f503e0fec97aec4e6141fc138cfb5e4dfd9ed8b99aaf740b56ed14485ab5e799c6f2ac93236e23b57cb7f39d25909c04b5727b1e926a836de1c6ad9359d
ssdeep: 3072:2+6HArlxi4Wk6O/OFCZisL4rZTSk8CytwNxIh5GURlSjgjxxt8v:2tH6xi8lmFCgsE1ekuUIh5LRlUivKv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160A38D1BA2842FD3CE8002B0251BCDCB6A283D955EAD5955EBF4C1CD339FDA8027E749
sha3_384: 138eb176a7771e2424f31d88fb06702ab07d0cd575c7c4ca3e088419a830a5ba11444fbaf80c2519419d8cc52f2f60f6
ep_bytes: 609090909090b800104000909090906a
timestamp: 1991-09-09 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.gSW@aW5A!Cf
CAT-QuickHealBackdoor.Padodor
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!9F7F4535163F
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.064ccf
ArcabitTrojan.ShellObject.E094A2
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.gSW@aW5A!Cf
NANO-AntivirusTrojan.Win32.Padodor.kfvvst
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.gSW@aW5A!Cf (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.gSW@aW5A!Cf
TrendMicroTROJ_GEN.R03BC0DLO23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9f7f4535163f0913
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.esrg
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.gSW@aW5A!Cf
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.3A62C3BB21
ALYacGen:Trojan.ShellObject.gSW@aW5A!Cf
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DLO23
RisingRansom.PornoAsset!8.6AA (TFE:2:dQq3nsYFyrD)
IkarusTrojan.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment