Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 0E5F63D53F42ABB17C7B.mlw
path: /opt/CAPEv2/storage/binaries/136e99a4a55aa13a01191568b7c7914f7065f467c209d772de4c8e0b200bff29
crc32: 6D4616DA
md5: 0e5f63d53f42abb17c7b0d0778706187
sha1: 4d3fe8c28a069b004b122d063c16b36c9ab53539
sha256: 136e99a4a55aa13a01191568b7c7914f7065f467c209d772de4c8e0b200bff29
sha512: 9c3ae3e36c50779c8543315f915dd9dcaafb5fba352c8d46cea696c7958b5398f2964bb88d206effde8be1f239a3ef2122d06d3d5e6b51f366dc9b3445d43bc1
ssdeep: 6144:1nNEu2htGDuMEUrQVad7nG3mbDp2o+SsmiMyhtHEyr5psPc1aj8DOvlvuZxriEl/:1NEuQtmuMtrQ07nGWxWSsmiMyh95r5Oa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A741A2FB3491772D28203B2360F59D6B72F9579236F85E0586C802D2367E3893BB6D5
sha3_384: 51e2212c1ff28092dce529fa1b39aed992cd3159988d5d9ff83910d3ffdd0c81a5380b36389af6eb5f84bf327aadbca1
ep_bytes: 90909090609067e80000000090909058
timestamp: 2012-04-24 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.w8Z@aq1NpPf
CAT-QuickHealBackdoor.Berbew.S30943575
SkyhighBehavesLike.Win32.Generic.fm
McAfeeTrojan-FVOK!0E5F63D53F42
Cylanceunsafe
VIPREGen:Trojan.ShellObject.w8Z@aq1NpPf
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.28a069
ArcabitTrojan.ShellObject.E153C3
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-29
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.w8Z@aq1NpPf
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.w8Z@aq1NpPf (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.Padodor.Win32.1425875
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.aiwh
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.HBYHFC
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.3ECE52881E
TACHYONBackdoor/W32.Padodor
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusBackdoor.Win32.Padodor
FortinetW32/Qukart.A!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment