Backdoor

What is “Backdoor:Win32/Padodor.SK!MTB”?

Malware Removal

The Backdoor:Win32/Padodor.SK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Padodor.SK!MTB virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Padodor.SK!MTB?


File Info:

name: CD7159466336598126F2.mlw
path: /opt/CAPEv2/storage/binaries/7b8ed28c36e00772648205c80503b121660a8664a5acd057763b72c1dd5382e0
crc32: 545C018E
md5: cd7159466336598126f21067ed6ab9e7
sha1: 66689f4b48dac4907f64873a52045a2ee43a11d1
sha256: 7b8ed28c36e00772648205c80503b121660a8664a5acd057763b72c1dd5382e0
sha512: 90b17be65dce8e1450040cc91e6e2eae4133170c195b653522ae4b5437cee3c735e97a5cd298bbe49a2e4d77b7f33ad741d3740e2bc651dc1047f84381bb072a
ssdeep: 3072:F3DA3yfNkREQ/vV8fo3PXl9Z7S/yCsKh2EzZA/z:GyfajVgo35e/yCthvUz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3B35BBBF3044F73C2BD0237710AA99DB7E594F90366C5821848F01E3617E2A527A6F6
sha3_384: fa58365de8e6bc93d226548443597c9d8a5bfda697f58a4470ad4572459ea05a620309eca19c934ddf1acc45c60f4f0d
ep_bytes: 90909090b80010400090bb38de400090
timestamp: 1980-09-26 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Padodor.SK!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.AB13442E.A.73054E7C
FireEyeGeneric.mg.cd71594663365981
SkyhighBehavesLike.Win32.Generic.ch
ALYacGeneric.Dacic.AB13442E.A.73054E7C
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.AB13442E.A.73054E7C
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGeneric.Dacic.AB13442E.A.73054E7C
K7GWTrojan ( 005780dd1 )
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderThetaAI:Packer.9F7E7E0821
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Barys-10002063-0
KasperskyBackdoor.Win32.Padodor.gen
RisingBackdoor.Padodor!8.118 (TFE:5:sru23FZbUHP)
TACHYONBackdoor/W32.Padodor
SophosML/PE-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebBackDoor.Wdozer
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.AB13442E.A.73054E7C (B)
IkarusTrojan.Win32.Padodor
JiangminBackdoor.Padodor.eyiy
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Padodor.SK!MTB
ArcabitGeneric.Dacic.AB13442E.A.73054E7C
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGeneric.Dacic.AB13442E.A.73054E7C
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Padodor.kp
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
Cybereasonmalicious.b48dac
AvastWin32:Padodor-V [Trj]

How to remove Backdoor:Win32/Padodor.SK!MTB?

Backdoor:Win32/Padodor.SK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment