Malware

Vundo.4 removal tips

Malware Removal

The Vundo.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Vundo.4 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Vundo.4?


File Info:

name: C296B66BBAB70EC4C058.mlw
path: /opt/CAPEv2/storage/binaries/c6a1ea4f3c2d2007df1aa716c3d3e4dbaece99b7659fe354d4dc635f57ac4903
crc32: C067368E
md5: c296b66bbab70ec4c058761d8c2b02dc
sha1: 39727eb4c341c972198fe7c178fba004171c5242
sha256: c6a1ea4f3c2d2007df1aa716c3d3e4dbaece99b7659fe354d4dc635f57ac4903
sha512: 0f163c9dd1d2bfbe4c15d698c8f79e9fc5db2304a886ce27786acff791f8bd23f3e55a349395590cd86314398d5090090893342a8d0f84d9334067cbbc8ce501
ssdeep: 1536:heo4iggxMlURnFw/tT7dHivte+0lvU+fIlkmND2Nls4FxlQXVSNqnUIoZl5eohPt:hV+6Fy4vkUMIrND2X3QLVHoxyIcQ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T166C3ADA17690807FC3E3117C59A2E32753FBAE684420594B2BE45ECF2E35582EA37357
sha3_384: 6d5ed3cb6703b640a9f4d1485a35c0f0266fe9553718fb007da40006180b12e05a82b1b078d9dcd320ee93bb56e3e4dd
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2001-08-22 10:14:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Canon BJ Mini Printer Driver
FileVersion: 6.0.5479.0 (vbl_wcp_d2_drivers.060616-1619)
InternalName: CNBOSTD.DLL
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CNBOSTD.DLL
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.0.5479.0
Translation: 0x0409 0x04b0

Vundo.4 also known as:

BkavW32.Common.A7735DDC
LionicTrojan.Win32.Menti.lpyg
tehtrisGeneric.Malware
DrWebTrojan.Click1.54947
MicroWorld-eScanGen:Variant.Vundo.4
FireEyeGeneric.mg.c296b66bbab70ec4
CAT-QuickHealTrojan.Vundo.27006
SkyhighVundo.gen.fy
ALYacGen:Variant.Vundo.4
Cylanceunsafe
ZillyaTrojan.Genome.Win32.200518
SangforTrojan.Win32.Vundo.Vwad
K7AntiVirusTrojan ( 004908121 )
AlibabaTrojan:Win32/Kryptik.4df8d272
K7GWTrojan ( 004908121 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36744.hu8@aOC9nidi
VirITTrojan.Win32.Generic.ZTZ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GND
TrendMicro-HouseCallTROJ_GEN.R03BC0OAT24
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Vundo.4
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:MalOb-GD [Cryp]
TencentWin32.Trojan.Generic.Azlw
TACHYONTrojan/W32.Vundo.123392.B
EmsisoftGen:Variant.Vundo.4 (B)
F-SecureTrojan.TR/Vundo.Gen
VIPREGen:Variant.Vundo.4
TrendMicroTROJ_GEN.R03BC0OAT24
SophosTroj/Virtum-Gen
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Genome.arnf
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Vundo.Gen
VaristW32/Virtumonde.CH.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumMalware@#2tr226pxzb3sf
ArcabitTrojan.Vundo.4
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Vundo.4
CynetMalicious (score: 100)
Acronissuspicious
McAfeeVundo.gen.fy
MAXmalware (ai score=100)
VBA32BScope.Trojan.Click
PandaTrj/Genetic.gen
RisingTrojan.Vundo!8.4FC (TFE:5:wY4YPM1KkuJ)
YandexTrojan.Genome!e09r8tfdaqI
IkarusGen.Variant.Vundo
FortinetW32/Kryptik.ANL!tr
AVGWin32:MalOb-GD [Cryp]
DeepInstinctMALICIOUS

How to remove Vundo.4?

Vundo.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment