Trojan

TrojanDropper:Win32/Vundo.J removal instruction

Malware Removal

The TrojanDropper:Win32/Vundo.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Vundo.J virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDropper:Win32/Vundo.J?


File Info:

name: BA83D1491499D19DDE6E.mlw
path: /opt/CAPEv2/storage/binaries/aa69f002147a5afbfe7cb729fab1381338fbb3fa20fd66f3d5323247f0ff3c27
crc32: F9C669B2
md5: ba83d1491499d19dde6e0dca841ee60f
sha1: cd8e0e01a7b3a949b6978798a7cd0853b872d1d4
sha256: aa69f002147a5afbfe7cb729fab1381338fbb3fa20fd66f3d5323247f0ff3c27
sha512: 590bdda71a8f63b4099fb52494e25d2513ed85936908558dcf714b4aaf456d5a203024e184327d35371d6d5fa9121cfe5f22869f47872f35a1fa8481c6cdcc7d
ssdeep: 1536:bAqcFccxtOI0m9KSyq4TPSoQYtBgUlTVG9245vWYC3b3QEkKMMiU1aoauY:OFJObKu7tBplT4vWTbgRKMMiU1m9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CFB3CE52F28029E6E1F382B1458F4515E275BCB011F3431FB79D37567EB02729EA2AA3
sha3_384: d446a6223f3c3f51497f491765b4e5d46c8a8eb9bb0c09d51b3025bdc38cacf51418e623b75d0a349aedc4f3b045bfe7
ep_bytes: 558bec6851580000528d97bc74799352
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: foobar2000.org
FileDescription: foobar2000
FileVersion: 0.9.2
LegalCopyright: © Peter Pawlowski. All rights reserved.
OriginalFilename: foobar2000_0.9.2.exe
ProductName: foobar2000
Translation: 0x0409 0x0000

TrojanDropper:Win32/Vundo.J also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Krap.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.IPZ.6
FireEyeGeneric.mg.ba83d1491499d19d
McAfeeGeneric Obfuscated.g
MalwarebytesMalware.AI.3020358574
VIPREGen:Heur.IPZ.6
SangforTrojan.Win32.Save.a
K7AntiVirusHacktool ( 005286a71 )
AlibabaTrojanDropper:Win32/Vundo.480283b6
K7GWHacktool ( 005286a71 )
Cybereasonmalicious.91499d
CyrenW32/Virtumonde.BY.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.LYS
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.io
BitDefenderGen:Heur.IPZ.6
AvastWin32:MalOb-DQ [Cryp]
EmsisoftGen:Heur.IPZ.6 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaDownloader.Mabu.Win32.35
TrendMicroTROJ_VUNDO.SMEO1
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.IPZ.6
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=98)
Antiy-AVLTrojan[Packed]/Win32.Krap
XcitiumTrojWare.Win32.Monder.wt@4fly69
ArcabitTrojan.IPZ.6
ZoneAlarmPacked.Win32.Krap.io
MicrosoftTrojanDropper:Win32/Vundo.J
GoogleDetected
AhnLab-V3Trojan/Win32.Vundo.R5628
Acronissuspicious
ALYacGen:Heur.IPZ.6
VBA32BScope.TrojanDropper.Vundo
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_VUNDO.SMEO1
RisingDropper.Vundo!8.6BA (TFE:5:4P7uS8X0bIF)
IkarusGen.Variant.Vundo
FortinetW32/Kryptik.IHN!tr
AVGWin32:MalOb-DQ [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Vundo.J?

TrojanDropper:Win32/Vundo.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment