Backdoor

Should I remove “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: A051A552DDD924BAF525.mlw
path: /opt/CAPEv2/storage/binaries/7ee990f91d18097eb3789b5cca22f233f55f6bf570d7823bc06c9cf9d274fec9
crc32: 69F25EB2
md5: a051a552ddd924baf525938fd1c2f932
sha1: f10f8eed80af954f5db0e97dfbb04416c4445592
sha256: 7ee990f91d18097eb3789b5cca22f233f55f6bf570d7823bc06c9cf9d274fec9
sha512: 7bd7c24e64daa76a2a8b6e1c975a56084b0b04cbe8c92194ebf46ff4ff5ada8156da1ddc1db62e613bcd2fbbee1c00d8be9ba7f5afefe32fdc785d2a12cf1d5f
ssdeep: 3072:hol9lXkbbavRSbTVf0/7v8qu1EmeFKPD375lHzpa1P:QfXkySbTVfq7v8qIEmeYr75lHzpaF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107A39E1BB2C11F93CA4506F8F17ECADFBA164F287265CCE118548888D31766D7AFA6C1
sha3_384: 5dae5e088ae0280405eadc3efb5001d3442d81cf38ffcd62627c01fd0cd6e4cca9604116e3435f4a2d075c59fe0f79ce
ep_bytes: 909090b80010400090bb38de4000b9f4
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.g8W@aiKV3eh
FireEyeGeneric.mg.a051a552ddd924ba
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXPE-AP!E55415C15965
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.ShellObject.g8W@aiKV3eh
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWin32.Padodor.V
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Malware.Padodor-10013598-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.g8W@aiKV3eh
NANO-AntivirusTrojan.Win32.Padodor.ixtcbs
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kl
TACHYONBackdoor/W32.Padodor
SophosMal/Generic-S
GoogleDetected
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.Wdozer
ZillyaTrojan.PadodorGen.Win32.16
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.g8W@aiKV3eh (B)
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.eybj
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitTrojan.ShellObject.E03BD9
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataWin32.Trojan.PSE.6Y5R0K
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
BitDefenderThetaAI:Packer.C486CAAD21
ALYacGen:Trojan.ShellObject.g8W@aiKV3eh
MAXmalware (ai score=85)
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Padodor!8.118 (TFE:5:hZCzzPv8nBJ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.d80af9
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment