Malware

Vundo.5 removal tips

Malware Removal

The Vundo.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Vundo.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Vundo.5?


File Info:

name: CC09BF80756BFB4F3E7A.mlw
path: /opt/CAPEv2/storage/binaries/ebd6aba429c70b314e21b91c4de66cb2f61569ff9cb148e6b16df9f93cef2129
crc32: 744BD370
md5: cc09bf80756bfb4f3e7ab8b7ebbbfdc9
sha1: 8ee44354542db602b8076aa0269a4c58c4f7d0a4
sha256: ebd6aba429c70b314e21b91c4de66cb2f61569ff9cb148e6b16df9f93cef2129
sha512: 2b1d9c5de4ee1b1004e3bd7133d1d8dee2cee5d5d635811a9347436f0c619e61bf9d08b27be0ac75c20f75f0de20ff2863d2cf90300b240cd87b732e43e2234d
ssdeep: 768:E8B0MmvlPB8kJPnkg4hVJp4F4Q+OHBFYihhpmvhVFQaOJKPEfomnrm2D6/j:r/mvpB8Q2hV74F4Qlt5GVF+0urNSj
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T104239DA23BB0C1B2F293A5B8715DC7766B55BE3450A0AC8776C30D8B2429822DD7172F
sha3_384: 4eed408cdcbad8a2dde8ad753ca687b8d4ca2130830a21615727d3d0eb5e173d8cf42c5caaf43ce930bc28c487942f01
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2008-12-04 00:41:51

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Media Center iTv Platform Low-Level Services
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: Microsoft.MediaCenter.Itv.Media.dll
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Microsoft.MediaCenter.Itv.Media.dll
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Vundo.5 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Vundo.5
FireEyeGeneric.mg.cc09bf80756bfb4f
CAT-QuickHealTrojan.Vundo.26446
SkyhighVundo.gen.fy
ALYacGen:Variant.Vundo.5
Cylanceunsafe
ZillyaAdware.SuperJuan.Win32.3168
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004908121 )
AlibabaAdWare:Win32/Virtumonde.e0f476c1
K7GWTrojan ( 004908121 )
BitDefenderThetaGen:NN.ZedlaF.36804.cu8@aS@KCtai
VirITTrojan.Win32.Vundo.MH
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Adware.Virtumonde.NHD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-1003510
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Vundo.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:MalOb-EI [Cryp]
TencentMalware.Win32.Gencirc.114e5a0f
TACHYONTrojan/W32.Vundo.47104.D
EmsisoftGen:Variant.Vundo.5 (B)
F-SecureTrojan.TR/Vundo.Gen
DrWebTrojan.Smardec.6
VIPREGen:Variant.Vundo.5
TrendMicroTROJ_GEN.R002C0PBC24
SophosMal/Generic-S
IkarusTrojan.Win32.Pirminay
GDataGen:Variant.Vundo.5
JiangminAdWare/SuperJuan.he
WebrootPua.Agent.Gen
VaristW32/Virtumonde.BZ.gen!Eldorado
AviraTR/Vundo.Gen
Antiy-AVLTrojan/Win32.Monder
Kingsoftmalware.kb.a.1000
XcitiumMalware@#20ahk1iqv98oa
ArcabitTrojan.Vundo.5
ZoneAlarmHEUR:Trojan.Win32.Generic
GoogleDetected
Acronissuspicious
McAfeeVundo.gen.fy
MAXmalware (ai score=99)
VBA32BScope.Trojan.Click
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PBC24
RisingTrojan.Vundo!8.4FC (TFE:5:GjBmulVV8FB)
YandexAdware.SuperJuan!0iG7QoLyxsU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.2432885.susgen
FortinetW32/Kryptik.ANL!tr
AVGWin32:MalOb-EI [Cryp]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Virtumonde.NHD

How to remove Vundo.5?

Vundo.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment