Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: A937B78E6E3523F1519F.mlw
path: /opt/CAPEv2/storage/binaries/ffc038979209ca55dc703d4a8a5a90545b831f020a6cde11fc26726a44d7d4a5
crc32: AE860439
md5: a937b78e6e3523f1519f9b7bfd1b5e62
sha1: 8c9cbf3e7236b43ecce1ed0a522b1609ef372771
sha256: ffc038979209ca55dc703d4a8a5a90545b831f020a6cde11fc26726a44d7d4a5
sha512: 4b4320bd350c6bc07663576e3cc72573970a02f253858e9903ab8aab5ebd0049beb55f6a385a611830fdbd67336f6867ae048988778fa9765fe5c59a167ff103
ssdeep: 1536:1vnsguJiGCKCOFhJMZHV53FLAnHfuLrfBJAduV9jojTIvjrH:uguwGeaqv9AHGLrfBJAd69jc0vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138A39D8E67721FBDFAC702B22A2E4B677565C17082BDC0925744634D242F86CDD3B6A2
sha3_384: 3766e6945b0cdd16a149c72dab68c2d20290787ef00416da0caa74bff01c35743a8f9a7fb6e6058f1c5f5702162dbe4c
ep_bytes: 9060909090b800104000bb38de400090
timestamp: 1986-03-19 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103285
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.a937b78e6e3523f1
SkyhighBehavesLike.Win32.Generic.nc
ALYacTrojan.GenericKDZ.103285
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.PadodorGen.Win32.15
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Padodor.58ae500e
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.911C0A761E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderTrojan.GenericKDZ.103285
NANO-AntivirusTrojan.Win32.Padodor.jxkncn
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPRETrojan.GenericKDZ.103285
TrendMicroTROJ_GEN.R002C0DLT23
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.103285 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.103285
JiangminTrojanSpy.Convagent.fp
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
KingsoftWin32.Hack.Padodor.gen
ArcabitTrojan.Generic.D19375
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!A937B78E6E35
MAXmalware (ai score=88)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLT23
RisingBackdoor.Padodor!8.118 (TFE:5:ostuCj5goYJ)
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.e7236b
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment