Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: E94C9E6765F7452FF80A.mlw
path: /opt/CAPEv2/storage/binaries/9a16afa965508a98586a34d04bc1016adae08c27e52e3d6401daf9db0e9b98d7
crc32: F1128CE2
md5: e94c9e6765f7452ff80acc406c9f5612
sha1: 2176e78290c0bcddf573d531e411618e13f8f2fb
sha256: 9a16afa965508a98586a34d04bc1016adae08c27e52e3d6401daf9db0e9b98d7
sha512: 3bb7f91cdf7efb2c430ce9524abf1ca4ba1d556f8fe91ac905a3ec12300e69f204281d68564ad3596e052ea0add8cea644e683e93ef74849b1ad8799341211a3
ssdeep: 1536:tlslkimHHnxFNkk1DnVODmu/Wblf2+Qfeous44PAadpyqqw2OM6bOLXi8PmCofGV:HsPmHXqk1Dn8Dmfblf2+QfeoLDPAadpU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170A39E5253172F71D79181F127E78DD7A2C9A3E853E880AEDC6CF40F814AD048ABF695
sha3_384: 0cb9e61bc32abd35cb9006c72ed277e630e63b038ce4081e8df68633b744219827b6d1bb55f6063c2c29d8542dd26604
ep_bytes: 6090909090b80010400090906a049090
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.f8W@aKzODno
FireEyeGeneric.mg.e94c9e6765f7452f
SkyhighBehavesLike.Win32.Generic.nc
ALYacGen:Trojan.ShellObject.f8W@aKzODno
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.13
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellObject.EDC170
BitDefenderThetaAI:Packer.89FC6AB71E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Obfus-38
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.f8W@aKzODno
NANO-AntivirusTrojan.Win32.Padodor.jvtpfw
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.f8W@aKzODno (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.f8W@aKzODno
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.eyhp
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.f8W@aKzODno
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!E94C9E6765F7
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:fGiz2IHxOJD)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.290c0b
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment