Backdoor

Backdoor:Win32/Padodor.SK!MTB information

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: 132F239509440D6A411E.mlw
path: /opt/CAPEv2/storage/binaries/dbfd5deced2aa5e635cc4fb0fb4dbee5d26c4ef5dba7e857b8d2baeb8b8384ba
crc32: 14DAF387
md5: 132f239509440d6a411effb9244f0330
sha1: 82b4912a630748e40407aba24d8c2b064aa689d2
sha256: dbfd5deced2aa5e635cc4fb0fb4dbee5d26c4ef5dba7e857b8d2baeb8b8384ba
sha512: adffbd0f1c83035390c7b35a72a730ada52c38468e5a9bcf44c7ec33b26781e4c436c2a411848bfdf2ea0278f1c385de1ed4a0741f53c785dfee7dc91f935411
ssdeep: 3072:VvFyLrP1u/Ihk+S8fo3PXl9Z7S/yCsKh2EzZA/z:VerPwIhk+Sgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DB37CF6E7700F72EE0203B17B45A3C6BB1A983913BB89427D68C12D121EF68DE75654
sha3_384: 14ed0a3ef6a755e191db376b487f7dd5aaa2e8d5946294daa544e673406c2dc4979c3bb71a3f4a34fc7134bc7f471c0d
ep_bytes: 90909090906067e80000000090909090
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.AB13442E.A.E8637324
FireEyeGeneric.mg.132f239509440d6a
SkyhighBehavesLike.Win32.Generic.ch
ALYacGeneric.Dacic.AB13442E.A.E8637324
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.AB13442E.A.E8637324
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGeneric.Dacic.AB13442E.A.E8637324
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.a63074
BitDefenderThetaAI:Packer.44E7344521
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Padodor.AB
APEXMalicious
ClamAVWin.Trojan.Crypted-31
KasperskyBackdoor.Win32.Padodor.gen
AlibabaBackdoor:Win32/Padodor.793bc22d
NANO-AntivirusTrojan.Win32.Padodor.jykdjy
RisingBackdoor.Berbew!8.115 (TFE:2:xj4tAqEbGWH)
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
ZillyaTrojan.Padodor.Win32.888398
TrendMicroTROJ_GEN.R002C0DH223
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.AB13442E.A.E8637324 (B)
IkarusTrojan.Crypt
JiangminBackdoor.Padodor.etpf
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
VaristW32/Backdoor.DKIC-2994
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGeneric.Dacic.AB13442E.A.E8637324
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGeneric.Dacic.AB13442E.A.E8637324
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeGenericRXAA-AA!132F23950944
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
VBA32Backdoor.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DH223
TencentBackdoor.Win32.Padodor.kp
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
AvastWin32:Padodor-V [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment