Getting rid of Vundo Trojan

Last update on August 11, 2008 12:03 PM by netsa77
Published by netsa77

Getting rid of Vundo Trojan




What is a Vundo Trojan?


Vundo is a particularly frustrating Trojan horse that causes popups and now and again causes flaws to the computer system by blocking the access to some websites like Google. The Trojan resides in the memory through the Internet browser’s setup program.

On Window’s operating systems, the DLL Trojan files are labeled as eight random upper and lower case characters and reside in the system32 directory. This will create hidden files, which will be located during a virus scanning process, instead of the DLL file itself.

How to remove a Vundo Trojan


There are several ways to get rid of the Vundo Trojan from your system

Manually



Step 1: Locate the Trojan


1. Open the “Start” menu and choose the “Search” option from the list.
2. Check the option “All files or folders” and in the section “All part or part of the file name”, enter “Vundo” in the field file name.
3. Set the option to search through your local drives or in the whole computer system by selcting “Look in: Local Hard Drives” or “Look in: My Computer”
4. Begin the process by clicking “Search”.
5. When the process is done, select the “Vundo” folder found and copy the path into the address bar. You should also save the same path on your clipboard as you will use it to delete the Vundo.

Step 2: Use Registry Editor to eliminate Registry Values


1. Open the Start menu and go to the “Run” option and enter “regedit” and click “OK”
2. Locate and remove the spywares that were searched earlier.
3. To remove the "Vundo" value, right-click and choose the "Delete" option from the list.
4. Browse for and delete "Vundo" registry entries:

HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainActiveState
02F96FB7-8AF6-439B-B7BA-2F952F9E4800
HKEY_LOCAL_MACHINESOFTWAREClassesATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINESOFTWAREClassesATLEvents.ATLEvents
8109AF33-6949-4833-8881-43DCC232B7B2
2316230A-C89C-4BCC-95C2-66659AC7A775
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce*[filename]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainActive StateHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOnce*WinLogon
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE SOFTWAREClassesCLSID{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents
HKEY_CLASSES_ROOTCLSID{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_CLASSES_ROOTCLSID{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunOnce*[filename]
HKEY_CURRENT_USER SoftwareMicrosoftWindows CurrentVersionRunOnce*WinLogon

Step 3: Using Command Prompt for Vundo unregistration


1. Go to the Start Menu and open the Run command.
2. Enter “cmd” and click “OK”
3. Enter “cd” to change the actual directory, leave a blank space and copy the Vundo DLL path saved and press the “Enter” key.
4. For unregistration, paste in the path directory together with "regsvr32 /u" + [DLL_NAME]” and press “Enter”

Download “Vundo” Trojan Romover Software


Download Link: http://www.wmsoftware.com/download.aspx?product=chktrust
Best answers for « Getting rid of Vundo Trojan » in :
How to get rid of Actulice/ No ModF/ Funk Popups ShowHow to get rid of Actulice/ No ModF/ Funk Popups Actulice is actually a Trojan that makes very annoying pop ups that will appear all over your screen. It starts with a small window that is displayed at the center of the screen and reads...
Uninstall Spybot Search and Destroy 1.6 ShowUninstall Spybot Search and Destroy 1.6 Add/Remove Programs Getting rid of Spybot-S & D 1.6 To uninstall Spybot Search & Destroy 1.6, follow these steps: Add/Remove Programs First, disable the program, then uninstall via ...
Cleaning the trojan- Vundo/Virtumonde ShowCleaning the trojan- Vundo/Virtumonde Intoduction Getting Started First Method : Vundofix Under Vista Intoduction Vundo also known as Virtumonde/Virtumondo is a trojan that download and displays popup and advertising for antispyware...
Download Trojan Remover ShowDescription: Especially designed to eliminate trojans (also called Trojan horses) as well as the intruders of ad ware and spy ware types, Trojan remover will help you to fight effectively against any sorts of spy software raging on...
Introduction to Trojan horses ShowTrojan horses A Trojan horseis a computer program which carries out malicious operations without the user's knowledge. The name "Trojan horse" comes from a legend told in the Iliad (by the writer Homer) about the siege of the city of Troy by the...
Viruses - Introduction to viruses ShowVirus A virus is a small computer program found within the body of another program which, when run, loads itself into the memory and carries out the instructions programmed by its author. The definition of a virus may be: « Any computer...
Igfxtray - igfxtray.exe Showigfxtray - igfxtray.exe The process igfxtray.exe (igfxtray) may indicate the presence of the Trojan horse Troj/PAdmin-A. How do you get rid of igfxtray.exe? Here is a list of tips to help you disinfect your machine and learn about the mechanisms of...