Backdoor

Backdoor:Win32/Padodor.SK!MTB malicious file

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: FFDFC1B6CFBC621FA716.mlw
path: /opt/CAPEv2/storage/binaries/c57681783fafbdf8b7bce8fd6dde394efc1785585a24ea14cee89b901a6d2e92
crc32: 979EE0F4
md5: ffdfc1b6cfbc621fa7169ff53292be4f
sha1: dc1ad083f83a7f7ef49c4b861492f772fcc737a2
sha256: c57681783fafbdf8b7bce8fd6dde394efc1785585a24ea14cee89b901a6d2e92
sha512: 81215fd4d4334c05ceb694cca737317ef70afc9dadaf662702c41631df0c6ad991478b37463a7c8c3bee3426932e80d13b081b981ca0994786108a98232dc199
ssdeep: 3072:COmKmGkoHEnMAMjWeyDpwoTRBmDRGGurhUI:COmDhokMppBm7UI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDA35C9A638C1F53D44602712A3F85D6F62EF1BF578640B104DA80EEE3E7A5C83791E9
sha3_384: 5a146bede63a971c9c4cfca82168fc8bd88727e43ed6bcf875d7fcf5ac3843a4f6948113f555bec65c3f443d08068112
ep_bytes: 609090909090b8001040009090909090
timestamp: 2016-06-02 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aqza5Lj
SkyhighBehavesLike.Win32.Generic.nc
McAfeeTrojan-FVOJ!FFDFC1B6CFBC
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.8
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.3f83a7
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-28
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aqza5Lj
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.g8W@aqza5Lj (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.g8W@aqza5Lj
SophosTroj/Padodor-M
IkarusBackdoor.Win32.Padodor
GDataGen:Trojan.ShellObject.g8W@aqza5Lj
JiangminBackdoor.Padodor.esac
VaristW32/Pahador.QLFO-8537
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.EC97D1
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.2F95F9791E
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment