Backdoor

VHO:Backdoor.Win32.Pandora removal guide

Malware Removal

The VHO:Backdoor.Win32.Pandora is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Backdoor.Win32.Pandora virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine VHO:Backdoor.Win32.Pandora?


File Info:

name: B372206040F23D120320.mlw
path: /opt/CAPEv2/storage/binaries/ca5061d14b01d0056f7209dc512728d317574578f273a6d934a8683d17c339b6
crc32: DD45803B
md5: b372206040f23d120320c12c9a0ac668
sha1: ab72cbd030b12d9dacf7b2564608d2fce735f8da
sha256: ca5061d14b01d0056f7209dc512728d317574578f273a6d934a8683d17c339b6
sha512: 8fc0b14c85196614ee6f705cfebcb7584d622a502486776d4a1b525508425f8a3c5999e23af05f3e4dc3a726d2d787a65f3e552399a6349d59a7ccddf1b7e311
ssdeep: 12288:vo0dAsBkSj9Mw5OJxiQZ5o7usYkioYqgUgU68mGb9U8ANt0EutfiLuPqwBVofB+Z:vovSjWSOHiQZ5ovhPU8AN4iFWnb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167259E3039C48833EDE250BA45ECF5224A7DE8B12B2246DB968D47FEC6247D17F36586
sha3_384: d6219b29ca1d7cb425b97d64ddc9104b59f7d53038e49495fc2766b49a060a15cc058e26ef0140a67fdef7edff3918c1
ep_bytes: e97c550400e95f150900e934770700e9
timestamp: 2022-09-01 16:00:10

Version Info:

0: [No Data]

VHO:Backdoor.Win32.Pandora also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.PWS.Siggen3.21710
MicroWorld-eScanGen:Variant.Lazy.238286
FireEyeGeneric.mg.b372206040f23d12
ALYacGen:Variant.Lazy.238286
CylanceUnsafe
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GenKryptik_AGen.KJ
KasperskyVHO:Backdoor.Win32.Pandora.gen
BitDefenderGen:Variant.Lazy.238286
AvastCrypterX-gen [Trj]
Ad-AwareGen:Variant.Lazy.238286
EmsisoftGen:Variant.Lazy.238286 (B)
VIPREGen:Variant.Lazy.238286
McAfee-GW-EditionPacked-GEP!B372206040F2
SentinelOneStatic AI – Suspicious PE
Trapminesuspicious.low.ml.score
IkarusTrojan.Win32.RedlineStealer
GDataGen:Variant.Lazy.238286
GoogleDetected
ArcabitTrojan.Lazy.D3A2CE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5200570
McAfeePacked-GEP!B372206040F2
APEXMalicious
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
AVGCrypterX-gen [Trj]

How to remove VHO:Backdoor.Win32.Pandora?

VHO:Backdoor.Win32.Pandora removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment