Backdoor

Should I remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C341CEF47D3207630634.mlw
path: /opt/CAPEv2/storage/binaries/dc5be6be221a5ebcb72b77b112b56ef29a660501f7fc2f4cdf2a6980de989563
crc32: 92C481F0
md5: c341cef47d32076306344b82f883cbee
sha1: 092dd60a56403a60188b72cf11c70197d0bcad7a
sha256: dc5be6be221a5ebcb72b77b112b56ef29a660501f7fc2f4cdf2a6980de989563
sha512: 82f4818d22fa112e882a43de1fa755fd66c1dfc44c469fa0874503ea045e3c4195dbaf96813a8a1de1020cbf5dd4fb0c7112ed280e085dc714a809ac6d20665f
ssdeep: 12288:kMrWq6t3XGCByvNv54B9f01ZmHByvNv5imipWf0Aq:k06t3XGpvr4B9f01ZmQvrimipWf0Aq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148846A5B73C53F72CF900DB0123E6499A61D9578FBA7E9BC5098C01DFAA6A18C33B191
sha3_384: ac75a306db0590431814def59406a6f8c19d5401c7c1d786226626e01ee8aa089544397e5de2b2f0f75d8a576c441241
ep_bytes: 90906090909067e80000000090589090
timestamp: 2019-02-27 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.y8Z@aqA82Sk
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.c341cef47d320763
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.fh
ALYacGen:Trojan.ShellObject.y8Z@aqA82Sk
Cylanceunsafe
ZillyaTrojan.QukartGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.bd82eca4
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a56403
BitDefenderThetaAI:Packer.924506AE21
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.y8Z@aqA82Sk
NANO-AntivirusTrojan.Win32.Padodor.foufls
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.y8Z@aqA82Sk (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.HangUp.5
VIPREGen:Trojan.ShellObject.y8Z@aqA82Sk
TrendMicroTROJ_GEN.R002C0DA124
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
IkarusTrojan.Crypt
GDataGen:Trojan.ShellObject.y8Z@aqA82Sk
JiangminBackdoor.Padodor.esac
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitTrojan.ShellObject.E3E9D4
ViRobotTrojan.Win.Z.Padodor.407557.RCT
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOK!C341CEF47D32
MAXmalware (ai score=87)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DA124
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.Win32.Padodor.gen
FortinetW32/GenKryptik.BJQV!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment