Trojan

Trojan:Win32/Vundo!G removal

Malware Removal

The Trojan:Win32/Vundo!G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vundo!G virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Vundo!G?


File Info:

name: 3BECCD02C4C5ECE8302F.mlw
path: /opt/CAPEv2/storage/binaries/198b6a6894019ef4f3372dfd1dd43ea4bd7f7a150671a464e2ccf9fa2f274234
crc32: AD994E36
md5: 3beccd02c4c5ece8302fd8769202d18f
sha1: 6d4fe8f4905541ef19c30b38c7bb2af70915abab
sha256: 198b6a6894019ef4f3372dfd1dd43ea4bd7f7a150671a464e2ccf9fa2f274234
sha512: eb6d36141e495b52a53ae389a362cd68b7e670e19a441efcc823cab3273fec8568c7143d80455fcbfcc50e507e2ff469167347a6bb6e448886c8f44207b98044
ssdeep: 1536:dpgaaW6tpZYLvJEeYdilJ07VcFRTBpoaeOMCLns2T3V1:dpghW86Lqe1UZcFTpoyMCLnsyv
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F383021BC71C6A5BDF5A103861BA9D7DCBB0D6B48F88582BD301CA2A5D8F1143ACD41D
sha3_384: 514d5fda4c5917655e9742826ba9c4944ccc88242172354750fb6a601e802e5cf65588c773b8fa051d30c425fa3c0c43
ep_bytes: 506870430210eb5f2264f183ea01e919
timestamp: 2008-05-08 19:35:33

Version Info:

0: [No Data]

Trojan:Win32/Vundo!G also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanMemScan:Trojan.Vundo.GPD
FireEyeGeneric.mg.3beccd02c4c5ece8
CAT-QuickHealTrojan.Vundo.Gen
SkyhighBehavesLike.Win32.Vundo.mc
ALYacMemScan:Trojan.Vundo.GPD
Cylanceunsafe
ZillyaTrojan.Monderb.Win32.3568
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Migotrup.1052ef69
VirITTrojan.Win32.Vundo.HC
SymantecTrojan.Vundo
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ADK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Vundo-53031
KasperskyTrojan.Win32.Migotrup.skx
BitDefenderMemScan:Trojan.Vundo.GPD
NANO-AntivirusTrojan.Win32.Plapon.bkwwi
ViRobotTrojan.Win32.A.Migotrup.83968.D
AvastWin32:MalOb-L [Cryp]
TACHYONTrojan/W32.Vundo.83968.BB
EmsisoftMemScan:Trojan.Vundo.GPD (B)
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.Virtumod.1771
VIPREMemScan:Trojan.Vundo.GPD
TrendMicroTROJ_VUNDO.SMF
Trapminemalicious.high.ml.score
SophosTroj/Virtum-Gen
IkarusVirus.Win32.Vundo
JiangminTrojan/Vundo.dos
WebrootW32.Trojan.Gen
VaristW32/Virtumonde.BJ.gen!Eldorado
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/Win32.Migotrup
KingsoftWin32.Trojan.Migotrup.skx
MicrosoftTrojan:Win32/Vundo.gen!G
XcitiumTrojWare.Win32.PkdKrap.Q@1j8qvd
ArcabitTrojan.Vundo.GPD
ZoneAlarmTrojan.Win32.Migotrup.skx
GDataMemScan:Trojan.Vundo.GPD
GoogleDetected
AhnLab-V3Win-Trojan/Virtumonde.Gen2
McAfeeVundo.gen.bh
MAXmalware (ai score=100)
VBA32BScope.Trojan.Virtumod
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_VUNDO.SMF
RisingTrojan.Kryptik!1.9990 (CLASSIC)
YandexTrojan.GenAsa!uU89i88+FJ0
SentinelOneStatic AI – Malicious PE
BitDefenderThetaAI:Packer.8EF7CC751E
AVGWin32:MalOb-L [Cryp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Vundo!G?

Trojan:Win32/Vundo!G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment