Remove Vundo. Description and removal instructions

 
Title: Vundo
Also known as: Vundo.b, Vundo.celldorado
Type: Trojans
Severity scale:Vundo severity is 92  (92 / 100)
 
Vundo trojan is a widely-spread trojan that displays large amount of unsolicited pop-up advertisements. Vundo is hard to remove, removal process is very compicated. Vundo and its mutated clones: Vundo.b, Vundo.celldorado also silently downloads aditional files from the Internet and runs arbitrary potentially harmful files, mostly adware components.
Vundo is distributed by e-mail in messages containing links to insecure web sites, which exploit certain security vulnerabilities of the Internet Explorer web browser. Once the user clicks on such a link, Internet Explorer opens a dangerous site that automatically installs the Vundo trojan into the system without user knowledge and consent.
Vundo is responsible for the severe decrease of the amount of system virtual memory available. This results in noticeable computer performance slowdowns. Vundo secretly runs on every Windows startup. Vundo creates a DLL file in the Windows system32 directory and writes registry entries, causing Windows to inject the file into winlogon.exe and many other programs.

There are some tools created to remove Vundo trojan. They called vundofix, they can fix certain variants of Vundo trojan.


Related files: vzbb.dll, vturr.dll

Vundo properties:
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Vundo removal:

remover for Vundo

Vundo manual removal:

Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\*WinLogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\*[filename]
HKEY_CLASSES_ROOT\CLSID\{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_CLASSES_ROOT\CLSID\{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Active State
Unregister DLLs:
vzbb.dll, vturr.dll

Delete files:
vzbb.dll, vturr.dll
Misc:
[filename] is a name of the trojan's main file.

The parasite creates infected executable files with random names. These files can be found in different folders inside C:\Windows or C:\Winnt directory.
Remove Vundo by following there steps. Manual and automated Vundo Fix.

Other programs to remove Vundo:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 12/10/05
Information updated: 22/03/08

Additional resources related to Vundo:

Attention: If you know or you have a website or page about Vundo removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Vundo parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by removed Vundo. 2008-03-19 17:03:45
Thank you for the instructions. I was able to remove Vundo succesfully

2. by Guest. 2007-02-04 02:02:57
ok


Related news:
Similar parasites:
Related articles:
Related discussions: