Remove Vundo. Description and removal instructions

 
Title: Vundo
Also known as: Vundo.b, Vundo.celldorado
Type: Trojans
Severity scale:Vundo severity is 92  (92 / 100)
 
Vundo trojan is a widely-spread trojan that displays large amount of unsolicited pop-up advertisements. Vundo is hard to remove, removal process is very compicated. Vundo and its mutated clones: Vundo.b, Vundo.celldorado also silently downloads aditional files from the Internet and runs arbitrary potentially harmful files, mostly adware components.
Vundo is distributed by e-mail in messages containing links to insecure web sites, which exploit certain security vulnerabilities of the Internet Explorer web browser. Once the user clicks on such a link, Internet Explorer opens a dangerous site that automatically installs the Vundo trojan into the system without user knowledge and consent.
Vundo is responsible for the severe decrease of the amount of system virtual memory available. This results in noticeable computer performance slowdowns. Vundo secretly runs on every Windows startup. Vundo creates a DLL file in the Windows system32 directory and writes registry entries, causing Windows to inject the file into winlogon.exe and many other programs.

There are some tools created to remove Vundo trojan. They called vundofix, they can fix certain variants of Vundo trojan.


Related files: vturr.dll, vzbb.dll, dszigqd.dll

Vundo properties:
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Vundo removal:

remover for Vundo

Vundo manual removal:

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\*WinLogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\*[filename]
HKEY_CLASSES_ROOT\CLSID\{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_CLASSES_ROOT\CLSID\{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Active State
Unregister DLLs:
vzbb.dll, vturr.dll

Delete files:
vzbb.dll vturr.dll dszigqd.dll
Misc:
[filename] is a name of the trojan's main file.

The parasite creates infected executable files with random names. These files can be found in different folders inside C:\Windows or C:\Winnt directory.
Remove Vundo by following there steps. Manual and automated Vundo Fix.

Other programs to remove Vundo:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 12/10/05
Information updated: 27/12/09

Additional resources related to Vundo:

Attention: If you know or you have a website or page about Vundo removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Vundo parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by . 2009-12-27 08:12:43
Mine came via Skype as message from a friend! went to all my contacts. Uninstalled AVG and will not let me to reinstall it.

2. by . 2009-10-13 08:10:01
Thanks, even though spyaware doctor isn't free and doesn't remove anything unless you buy it it detected some smaller adware I didn't know I had and I was able to remove it.

3. by . 2008-10-17 08:10:30
I have vundo from MININOVA

4. by . 2008-09-28 15:09:46
Spybot finds vundo but didnt actually remove it for real, I ran it several times.

Malwarebytes Malware remover killed it for real.

Both are free.

5. by biggot. 2008-09-05 13:09:10
hey thats funny. i got my vundo there too. mine was from mininova.

PEOPLE, AVOID DOWNLOADING PS2 EMULATORS FROM TORRENT SITES. GO TO THE ORIGINAL SITES INSTEAD.

6. by . 2008-07-03 11:07:01
running spybot search&destroy now and so far it has found most if not all the items above also. i picked this little sucker up off a ps2 emulator .rar file i got from a torrent down load also so be careful of .rar files that may be suspicious.

7. by removed Vundo. 2008-03-19 17:03:45
Thank you for the instructions. I was able to remove Vundo succesfully

8. by Guest. 2007-02-04 02:02:57
ok


Related news:
Similar parasites:
Related articles:
Related discussions: