Trojan

How to remove “Trojan:Win32/Vundo!G”?

Malware Removal

The Trojan:Win32/Vundo!G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vundo!G virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Vundo!G?


File Info:

name: 8DF7CB24577014029541.mlw
path: /opt/CAPEv2/storage/binaries/4831dd8321903d67e383ca6ab6b527f4379b60b1ae468decd86a1cc9fab3bd0f
crc32: D3E53B5B
md5: 8df7cb245770140295412fc43ab6efd9
sha1: a726833ab3eb2a82f11815881ee1c8023168f091
sha256: 4831dd8321903d67e383ca6ab6b527f4379b60b1ae468decd86a1cc9fab3bd0f
sha512: d8759a5b5103a1e1b0da1d6f2f28dc32163222c3a50e61d3200b9d80847cc35b29b923018e379f173baabf6be8d7e99ed710146cc196c0f1eb27e87e1cb04bea
ssdeep: 1536:F+Y8pNZ8P92Ok9MOQhjvB7udqrHa3G2UgE8y6pFia9Ezjja:FKi92Ok9zQhDBikDng3pFx9l
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F783025886CC4E63E24954B819560231B3FFF64D8FF9734A2798E8A2C05B1689DFF48D
sha3_384: 856cee1f56e4bb0c4522f769fed5d6cb01b76ddd04927bf66378b759b60c245790d9f0ad294b5a7934bb7065621c92fd
ep_bytes: 506870430210e96efdffff0b742410d3
timestamp: 2008-05-08 19:09:53

Version Info:

0: [No Data]

Trojan:Win32/Vundo!G also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Krap.mDLY
Elasticmalicious (high confidence)
DrWebTrojan.Virtumod.1771
MicroWorld-eScanTrojan.Vundo.GPL
FireEyeGeneric.mg.8df7cb2457701402
CAT-QuickHealTrojan.Vundo.Gen
SkyhighBehavesLike.Win32.Vundo.mc
McAfeeVundo.gen.bh
VIPRETrojan.Vundo.GPL
AlibabaTrojan:Win32/Migotrup.be87520e
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.FF1047391E
VirITTrojan.Win32.Vundo.HC
SymantecTrojan.Vundo
ESET-NOD32a variant of Win32/Kryptik.ADK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Migotrup.skx
BitDefenderTrojan.Vundo.GPL
NANO-AntivirusTrojan.Win32.Monderb.bkyzo
AvastWin32:MalOb-L [Cryp]
TencentWin32.Trojan.Migotrup.Cnhl
TACHYONTrojan/W32.Vundo.84992.CU
EmsisoftTrojan.Vundo.GPL (B)
F-SecureTrojan.TR/ATRAPS.Gen2
ZillyaTrojan.Monderb.Win32.3715
TrendMicroTROJ_VUNDO.ILYS
SophosTroj/Virtum-Gen
IkarusVirus.Win32.Vundo
GDataTrojan.Vundo.GPL
JiangminTrojan/Vundo.dlk
WebrootW32.Vundo.Gen
GoogleDetected
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/Win32.Migotrup
Kingsoftmalware.kb.b.989
XcitiumTrojWare.Win32.PkdKrap.Q@1j8qvd
ArcabitTrojan.Vundo.GPL
ViRobotAdware.Virtumonde.84992.AXD
ZoneAlarmTrojan.Win32.Migotrup.skx
MicrosoftTrojan:Win32/Vundo.gen!G
VaristW32/Virtumonde.BJ.gen!Eldorado
AhnLab-V3Win-Trojan/Virtumonde.Gen2
VBA32BScope.Trojan.Virtumod
ALYacTrojan.Vundo.GPL
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_VUNDO.ILYS
RisingTrojan.Kryptik!1.9990 (CLASSIC)
YandexTrojan.GenAsa!uU89i88+FJ0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:MalOb-L [Cryp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Vundo!G?

Trojan:Win32/Vundo!G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment