Trojan

How to remove “Trojan:Win32/Vundo!AA”?

Malware Removal

The Trojan:Win32/Vundo!AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vundo!AA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Vundo!AA?


File Info:

name: F3D652C46DF0A173DB27.mlw
path: /opt/CAPEv2/storage/binaries/d5a117a765c9d53f23344d15c9f0dae29feb393644cbe5d4983af50f69b3e526
crc32: 6D66BA76
md5: f3d652c46df0a173db275ead6f862c68
sha1: bdce8d65286903d785a9d19bbc1eaf5937da7c6c
sha256: d5a117a765c9d53f23344d15c9f0dae29feb393644cbe5d4983af50f69b3e526
sha512: f9e6599126ea054c4c81be7e013b10ebd20f11fad56e613520f7b802b4bb84edc0364cb70e41108edd4746362b71a2bef57f2d9b8945e443a59ee46057723c89
ssdeep: 768:3wJYfN7EEl6f1tCIuPmTP+NIZe/cnVmVkovcWw2l2eKbjROi9PiOSJ2QG4Yx:gaFdlu7oWPZIkVVucWJAe6N9PirJxGbx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D243BF87796ECAD5DDC789FACC8B2D1631477AA4FA02CF13620C29692E65435E13EF04
sha3_384: 4bc4c2fe1d8a7834df35d8dd02f270b9677a09e4cbbc0604564976b6ba5f22f1374c3ed76573e50bb716282468b97b8b
ep_bytes: 558bec538b5d08568b750c85f6578b7d
timestamp: 1975-04-24 18:19:06

Version Info:

0: [No Data]

Trojan:Win32/Vundo!AA also known as:

BkavW32.CNCmonder.Heur
LionicTrojan.Win32.Generic.laTc
AVGWin32:Susn-C [Trj]
MicroWorld-eScanTrojan.Vundo.Gen.4
FireEyeGeneric.mg.f3d652c46df0a173
SkyhighBehavesLike.Win32.VirRansom.qc
McAfeeVundo
MalwarebytesTrojan.Vundo
ZillyaTrojan.Monder.Win32.801
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Monderd.839e81fb
Cybereasonmalicious.46df0a
VirITTrojan.Win32.Vundo.FI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.Virtumonde.NDI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Vundo-10100
KasperskyTrojan.Win32.Monderd.gen
BitDefenderTrojan.Vundo.Gen.4
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Susn-C [Trj]
TencentWin32.Trojan.Monderd.Vimw
TACHYONTrojan/W32.Monder.56320.O
SophosTroj/Virtum-Gen
F-SecureTrojan.TR/Drop.Agent.NAO
DrWebTrojan.Virtumod.853
VIPRETrojan.Vundo.Gen.4
TrendMicroTROJ_VUNDO.SMAD
Trapminemalicious.high.ml.score
EmsisoftTrojan.Vundo.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Monder.alrj
VaristW32/Trojan.CDHO-4977
AviraTR/Drop.Agent.NAO
Antiy-AVLTrojan/Win32.Monderd
KingsoftWin32.Trojan.Monderd.gen
MicrosoftTrojan:Win32/Vundo.gen!AA
XcitiumTrojWare.Win32.Virtumonde.~AF@yihb
ArcabitTrojan.Vundo.Gen.4
ViRobotTrojan.Win32.Monder.56320.Q
ZoneAlarmTrojan.Win32.Monderd.gen
GDataTrojan.Vundo.Gen.4
GoogleDetected
AhnLab-V3Trojan/Win32.Vundo.R9398
BitDefenderThetaAI:Packer.8F79D2811E
ALYacTrojan.Vundo.Gen.4
MAXmalware (ai score=100)
VBA32BScope.Trojan.Monderd
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_VUNDO.SMAD
RisingTrojan.Vundo!8.4FC (TFE:3:MMFCWBe7ewN)
IkarusPacker.Win32.Tdss
MaxSecureTrojan.Monderd.gen
FortinetW32/Vundo.GAL!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Virtumonde.NDI

How to remove Trojan:Win32/Vundo!AA?

Trojan:Win32/Vundo!AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment