Trojan

Trojan:Win32/Vundo.JD.dll (file analysis)

Malware Removal

The Trojan:Win32/Vundo.JD.dll is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vundo.JD.dll virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Vundo.JD.dll?


File Info:

name: BF934B6DD0F510E46B9B.mlw
path: /opt/CAPEv2/storage/binaries/82f5a0d614a04a1ad6afd6b19f80ccaa77bd801eeef869eceaeb8aca6dfeaed8
crc32: C94D5119
md5: bf934b6dd0f510e46b9b36d5676864d4
sha1: 287ed3adeb58867a2e89d18ffabc7fc29e32c0f0
sha256: 82f5a0d614a04a1ad6afd6b19f80ccaa77bd801eeef869eceaeb8aca6dfeaed8
sha512: 6121faf411d511bb1de46a3c2b293284ddf00484a91e38ccd7302ee3211b993041d950a12087fc63ec950a562e414ac16fb2c623ea1edb3bb229b46555dc6b04
ssdeep: 1536:YSls8NaW57/9mzY4WC1c+NrD84rmE4CjbpEBbEb:FRIw/ZC1c+NrV94sb2BbEb
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1E863F13393F44D61FC63793B23F0C30A643E2EA89470535599D00B937A69584BA78BAE
sha3_384: e596f81132d14fafbfafee80c3ee13f4ef9d0f2aa4b9c622631aaeda84909449ff6eb6f69874e35784820bcea301abef
ep_bytes: 558bec516a956aaa6a9b6838315a1954
timestamp: 2007-12-07 02:21:45

Version Info:

Comments:
CompanyName: ABBYY (BIT Software)
FileDescription: Lingvo Keyboard Hook DLL
FileVersion: 10.0.0.213
InternalName: LvHook
LegalCopyright: Copyright © 2004 ABBYY Software Ltd.
LegalTrademarks: ABBYY® Lingvo®, ABBYY Lingvo Tutor (tm) are trademarks or registered trademarks of ABBYY Software Ltd.
OriginalFilename: LvHook.dll
ProductName: Lingvo
ProductVersion: 10.0.0.213
Translation: 0x0409 0x00b0

Trojan:Win32/Vundo.JD.dll also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Mondera.kYPF
tehtrisGeneric.Malware
ClamAVWin.Spyware.58598-2
CAT-QuickHealTrojan.Vundo.Gen
SkyhighBehavesLike.Win32.Vundo.kc
McAfeeVundo.gen.u
Cylanceunsafe
VIPREGen:Heur.Krypt.12
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f10007011 )
BitDefenderGen:Heur.Krypt.12
K7GWTrojan ( f10007011 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Krypt.12
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Adware.Virtumonde
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaVirTool:Win32/Obfuscator.7f31a020
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.PSWIGames.66679
MicroWorld-eScanGen:Heur.Krypt.12
RisingTrojan.Win32.VUNDO.cbi (CLASSIC)
EmsisoftGen:Heur.Krypt.12 (B)
F-SecureTrojan.TR/Vundo.Gen
DrWebTrojan.Virtumod.based.25
ZillyaTrojan.OnLineGames.Win32.7823
TrendMicroMal_Vundo-15
FireEyeGeneric.mg.bf934b6dd0f510e4
SophosTroj/Virtum-Gen
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.BHO.adr
VaristW32/Virtumonde.AL.gen!Eldorado
AviraTR/Vundo.Gen
MAXmalware (ai score=78)
Antiy-AVLTrojan[Downloader]/Win32.BHO
KingsoftWin32.Troj.PackerUndefT.eh.67650
XcitiumTrojWare.Win32.Trojan.Vundo.GenT@1nhc10
MicrosoftTrojan:Win32/Vundo.JD.dll
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Krypt.12
GoogleDetected
AhnLab-V3Win-Trojan/Vundo6.Gen
DeepInstinctMALICIOUS
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.4147470987
PandaSpyware/Virtumonde
TrendMicro-HouseCallMal_Vundo-15
TencentMalware.Win32.Gencirc.10b21603
YandexTrojan.Vundo.Gen!Pac.25
IkarusPacker.Win32.Mondera
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Vundo.fam!tr
BitDefenderThetaAI:Packer.2E9722291F
AVGWin32:Vupa [Cryp]
AvastWin32:Vupa [Cryp]
alibabacloudTrojan:Win/Krypt

How to remove Trojan:Win32/Vundo.JD.dll?

Trojan:Win32/Vundo.JD.dll removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment