Malware

Vundo.13 removal

Malware Removal

The Vundo.13 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Vundo.13 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Japanese
  • Authenticode signature is invalid

How to determine Vundo.13?


File Info:

name: 82D61F0FFB8991B33014.mlw
path: /opt/CAPEv2/storage/binaries/833897ecc435867a97b28744fec0d112245b889fc62f5b84b4e19f5de92504e2
crc32: 8FE74C7F
md5: 82d61f0ffb8991b3301476d50d232a51
sha1: f70ac78e5ab16b501f08aae1180e681931e7a132
sha256: 833897ecc435867a97b28744fec0d112245b889fc62f5b84b4e19f5de92504e2
sha512: 60080246cb60ea41c22ed5f3865b1a66123fbefe044ef54ff68bb6323a68b597e45554f9a2a4af594f817138a2319cbbad6c9c5a7d9af12952dfb2672e30a2e4
ssdeep: 1536:FooPaqZgKAQyyzURJEApbWgaE/GSwIdWwgoUD4vA7jnmDwRfojeoKoZW0y:OoCqOKAy3ApbvulIPIDWA7jneHjeoKo/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13193BE61BBA680B7D2C76234556AD727973A7F2428F1A4873FE22D532D30501C723B6B
sha3_384: 8de452f83ef46c5298d44460b609e1660f643f55a88e468dd204c9dfe28c29e5be8ff6218f8d5bcbd6e8632c585ff1a5
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 1999-04-23 12:31:46

Version Info:

CompanyName: Ejlwccyyz Drksjuvlnje
FileDescription: Drslhxwea IME 2002
FileVersion: 8.1.3124.0
InternalName: MS-IME 2002
LegalCopyright: Copyright (C) 1995-2000 Qfcjsgkmv Zmsfkjxzypx. All rights reserved.
LegalTrademarks: XruycnsnrR is a registered trademark of Nikighixo Euphcltvnkl. Xqfinny(TM) is a trademark of Eymmzioeq Wqkjbukmmtj
OriginalFilename: IMEPADSM.DLL
ProductName: Rwweklwyu IME 2002
ProductVersion: 8.1.3124.0
Translation: 0x0000 0x04b0

Vundo.13 also known as:

LionicTrojan.Win32.Monder.4!c
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Vundo-79837
SkyhighVundo.gen.fy
McAfeeVundo.gen.fy
Cylanceunsafe
ZillyaTrojan.Monder.Win32.45917
SangforTrojan.Win32.Kryptik.NDT
K7AntiVirusTrojan ( 004908121 )
BitDefenderGen:Variant.Vundo.13
K7GWTrojan ( 004908121 )
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.NDT
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.5bbf5fe7
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.A.Monder.91136
MicroWorld-eScanGen:Variant.Vundo.13
AvastWin32:MalOb-GD [Cryp]
TencentWin32.Trojan.Vundo.Hajl
TACHYONTrojan/W32.Vundo.91136.AG
SophosTroj/Virtum-Gen
F-SecureTrojan.TR/Vundo.Gen
DrWebTrojan.Juan.432
VIPREGen:Variant.Vundo.13
FireEyeGeneric.mg.82d61f0ffb8991b3
EmsisoftGen:Variant.Vundo.13 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare/SuperJuan.mn
WebrootW32.Trojan.Superjuan.Gen
VaristW32/Virtumonde.CH.gen!Eldorado
AviraTR/Vundo.Gen
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Ditertag.A
XcitiumMalware@#1uz7v8can20fh
ArcabitTrojan.Vundo.13
SUPERAntiSpywareTrojan.Agent/Gen-Falprod[Cont]
ZoneAlarmUDS:Trojan.Win32.Generic
GDataGen:Variant.Vundo.13
GoogleDetected
ALYacGen:Variant.Vundo.13
MAXmalware (ai score=100)
VBA32BScope.Trojan.Click
PandaTrj/CI.A
RisingTrojan.Ymacco!8.11BE1 (TFE:5:1P2gKBy2hcC)
YandexTrojan.Monder!fhhb7DRaMKc
IkarusTrojan.Win32.Pirminay
MaxSecureTrojan.Malware.2176570.susgen
FortinetW32/Monder.BMF!tr
BitDefenderThetaGen:NN.ZedlaF.36744.fu8@aav1xMgG
AVGWin32:MalOb-GD [Cryp]
DeepInstinctMALICIOUS

How to remove Vundo.13?

Vundo.13 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment