Backdoor

Backdoor:Win32/Padodor.SK!MTB removal tips

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: C1A3B8A3078771ADD4BA.mlw
path: /opt/CAPEv2/storage/binaries/6a0c0cf71f7e3b168b8a102c5eee842ac52d1730689778405085627908a7a3b2
crc32: DD042A47
md5: c1a3b8a3078771add4ba53e82500e74c
sha1: 94b01d64d4784d30ae8b64ad41ad65eec6463c5b
sha256: 6a0c0cf71f7e3b168b8a102c5eee842ac52d1730689778405085627908a7a3b2
sha512: c58bf39614b3c40b2782e984a2bc2b4c7d1601cdc930df2a4947aa98c829bb2fe3af7192f474bed3e46c81207e56b8ffd94fc8f89b9b2fce60886c52d059d257
ssdeep: 3072:IdbCPBYgJV0XzFvTqAelSJdEN0s4WE+3S9pui6yYPaI7DX:Idmig4icENm+3Mpui6yYPaI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9D38C0B361B2F26C4DE07F0580B099D7776D52A12394DE419ECC25E3746F2863BB29B
sha3_384: 2a7c38002ebaa45b929887b6a12455cddd0eab81a71e4c001cb9a8338855d5b5360f64e122c6241b734327c8b3e22488
ep_bytes: 90906090909067e80000000090589090
timestamp: 2017-10-15 03:39:59

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c1a3b8a3078771ad
SkyhighBehavesLike.Win32.Generic.cc
ALYacGen:Trojan.ShellObject.i8Z@aGN6KMb
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.i8Z@aGN6KMb
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.e07fd607
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.NAM
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.i8Z@aGN6KMb
NANO-AntivirusTrojan.Win32.Padodor.foufls
MicroWorld-eScanGen:Trojan.ShellObject.i8Z@aGN6KMb
AvastWin32:BackdoorX-gen [Trj]
TencentBackdoor.Win32.Padodor.kg
TACHYONBackdoor/W32.Padodor
EmsisoftGen:Trojan.ShellObject.i8Z@aGN6KMb (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.HangUp.5
ZillyaTrojan.PadodorGen.Win32.7
TrendMicroTROJ_GEN.R002C0DAN24
Trapminemalicious.high.ml.score
SophosTroj/Padodor-M
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1G33IXO
JiangminBackdoor.Padodor.brul
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitTrojan.ShellObject.E01D67
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
VaristW32/Pahador.QLFO-8537
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOK!C1A3B8A30787
MAXmalware (ai score=89)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAN24
RisingBackdoor.Berbew!1.AF13 (CLASSIC)
YandexBackdoor.Padodor.AF
IkarusTrojan-Downloader.Win32.Berbew
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.E277728A21
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment