Trojan

Trojan:Win32/Vundo.A removal

Malware Removal

The Trojan:Win32/Vundo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vundo.A virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan:Win32/Vundo.A?


File Info:

name: F0B105A40CDC5B12A4C0.mlw
path: /opt/CAPEv2/storage/binaries/b7ffa7b8776df0784c2f78047219de00c1ddc28e7499509335f07782ff4886a1
crc32: CB1B1769
md5: f0b105a40cdc5b12a4c0d7598eddf3b2
sha1: 877ec838871e5e3dd55c52e315b06e91f5f5581a
sha256: b7ffa7b8776df0784c2f78047219de00c1ddc28e7499509335f07782ff4886a1
sha512: d0eebb56adbacd183dc34db110c0a9315991c1add6e2f01c461e36419fd6b97949e5d1b8b6d79f8678f02318f00b13f454cd09ac672ba7eb38f9bb9400749b46
ssdeep: 24576:RyWFUM1WsNUibHIHCes4d2ZfctLUk5wXBXZqsTpAnU:RvFUM1WiUiLIiO2ZfcZUkGxQsTd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161054A21F742E01BF9A700B2A96D466AB15C6B304B4444C7F3C89F6D677D6D2AE3231B
sha3_384: 6047e78f3ac3baed077fac4f70b84382718d3e93292bd66cfc3e3c304d3ce6b7a9739ac523dd21f60902b0b6b12f31bc
ep_bytes: 6a606898854a00e8af100000bf940000
timestamp: 2004-11-12 16:35:54

Version Info:

0: [No Data]

Trojan:Win32/Vundo.A also known as:

LionicAdware.Win32.Virtumonde.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Virtumod
MicroWorld-eScanGen:Trojan.Heur.PT.0qW@bqE6vuhi
FireEyeGeneric.mg.f0b105a40cdc5b12
SkyhighBehavesLike.Win32.Suspicious.ch
McAfeeAdware-Virtumundo.e
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Trojan.Heur.PT.0qW@bqE6vuhi
SangforSpyware.Win32.Virtumonde.Vk3y
K7AntiVirusSpyware ( 000086711 )
AlibabaTrojanSpy:Win32/Virtumonde.a5014147
K7GWSpyware ( 000086711 )
Cybereasonmalicious.40cdc5
BitDefenderThetaAI:Packer.174CFC991F
VirITTrojan.Win32.Agent.ELM
SymantecTrojan.Vundo
ESET-NOD32Win32/Spy.Agent.NAE
TrendMicro-HouseCallTROJ_VUNDO.C
ClamAVWin.Dropper.Virmo-3
KasperskyTrojan.Win32.Virtumonde.f
BitDefenderGen:Trojan.Heur.PT.0qW@bqE6vuhi
NANO-AntivirusTrojan.Win32.Agent.bafcf
AvastWin32:Agent-DQP [Trj]
SophosTroj/Virtum-Gen
F-SecureTrojan.TR/Spy.Agent.L.14
ZillyaTrojan.Agent.Win32.21916
TrendMicroTROJ_VUNDO.C
CMCGeneric.Win32.f0b105a40c!MD
EmsisoftGen:Trojan.Heur.PT.0qW@bqE6vuhi (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=95)
JiangminTrojanDropper.Agent.dpo
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Spy.Agent.L.14
VaristW32/Dhalsim.EAYG-8371
Antiy-AVLTrojan/Win32.Virtumonde
KingsoftWin32.HeurC.KVM003.a
MicrosoftTrojan:Win32/Vundo.A
XcitiumTrojWare.Win32.Spy.Agent.NAE@2ws4
ArcabitTrojan.Heur.PT.ECFF6B
ViRobotTrojan.Win32.A.Virtumonde.856064
ZoneAlarmTrojan.Win32.Virtumonde.f
GDataGen:Trojan.Heur.PT.0qW@bqE6vuhi
CynetMalicious (score: 100)
VBA32BScope.Trojan.Swisyn
ALYacGen:Trojan.Heur.PT.0qW@bqE6vuhi
Cylanceunsafe
PandaSpyware/Virtumonde
RisingTrojan.Spy.Agent.cgp (CLASSIC)
YandexTrojan.DR.Agent!H8GjNZ06LPk
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.1210886.susgen
FortinetW32/Virtumonde.F!tr
AVGWin32:Agent-DQP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Vundo.A?

Trojan:Win32/Vundo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment