Backdoor

About “Backdoor:Win32/Padodor.SK!MTB” infection

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 05E7A535CA8C80026650.mlw
path: /opt/CAPEv2/storage/binaries/fcaa440dc0cf6503d98a8d406c3f0e217bd29075c16a69b8f0620f995a20b063
crc32: 8A2D9106
md5: 05e7a535ca8c8002665068235fbd0a1b
sha1: 15b9d34a578c0f4dd0e531b585b79f0e7a2a4db1
sha256: fcaa440dc0cf6503d98a8d406c3f0e217bd29075c16a69b8f0620f995a20b063
sha512: 84ac04d52874a92442216a346b71864493253fe082b76b6d53dfc2b3f1978cf48f50d10f6e9055621726388042bb23d31203bafb3dd0bf6ede5d180d73768f33
ssdeep: 3072:BM4yzbpqslDcgmtmfH/bvI+aH8fo3PXl9Z7S/yCsKh2EzZA/z:ubp3lDcrmnbvI+aHgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0B36C8B72609FA3D77203B3370D98C5B3F8877556AF85D17A34C05CA20EA9C567E286
sha3_384: f4427ee839fdbe4114823ddfcc27ce05fbf42464d9294728dd4097beb736054eb52669e4362d44e8a0506184d8725c27
ep_bytes: 9090909090b800104000bb38de400090
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
ClamAVWin.Trojan.Crypted-28
FireEyeGeneric.mg.05e7a535ca8c8002
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Trojan.ShellObject.g8W@aKrr!2b
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.a4c1d90a
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.9F7E7E0821
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aKrr!2b
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aKrr!2b
AvastWin32:Padodor-V [Trj]
RisingBackdoor.Padodor!8.118 (TFE:5:sru23FZbUHP)
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.g8W@aKrr!2b
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.g8W@aKrr!2b (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ShellObject.g8W@aKrr!2b
JiangminBackdoor.Padodor.exyj
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitTrojan.ShellObject.EF8CB9
ZoneAlarmBackdoor.Win32.Padodor.gen
MicrosoftBackdoor:Win32/Padodor.SK!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXAA-AA!05E7A535CA8C
MAXmalware (ai score=83)
VBA32Backdoor.Padodor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.a578c0
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment