Removing Trojan Vundo with FixVundo.exe from Symantec

This section provides a tutorial example of how to remove trojan Vundo with FixVundo.exe from Symantec.

As I mentioned in my previous tutorial, my first choice was to use the tool and instruction provided by Symantec at: http://www.symantec.com/security_response/writeup.jsp?docid=2004-112210-3747-99

1. Downloaded FixVundo.exe from http://securityresponse.symantec.com/avcenter/FixVundo.exe:

11/04/2006  08:51 AM           166,064 FixVundo.exe
File properties: 
   File version: 1.5.0.0
   Copyright: Copyright(C) 2004 Symantec Corporation

2. Closed all applications and disconnect from the Internet.

3. Disabled Windows System Restore function to avoid Trojan Vundo hiding in the restore area:

Click Start >> My Computer
Right-mouse click and select Properties. Properties dialog box displays.
Click System Restore tab
Check "Turn of System Restore" checkbox
Click Apply

4. Ran FixVundo.exe and clicked the Start button. It started to scan the entire hard disk. This took about 20 minutes. Surprisingly, FixVundo reported no Vundo infections.

But when I looked at the log file, FixVundo.log, I saw this:

Symantec Trojan.Vundo Removal Tool 1.5.0

The process "explorer.exe" contained a viral thread (00000444). 
   The thread was terminated.

The process "explorer.exe" contained a viral thread (00000450). 
   The thread was terminated.

Trojan.Vundo has not been found on your computer.

Conclusion: The latest version of FixVundo 1.5.0 from Symantec was not able to detect the Trojan Vundo files. But it did find some issues in the running explorer.exe process.

Table of Contents

 About This Book

 Introduction to Microsoft Windows

 Introduction to Windows Explorer

 Introduction to Internet Explorer

 "Paint" Program and Computer Graphics

 GIMP - GNU Image Manipulation Program

 JPEG Image File Format Quality and Size

 GIF Image File Format and Transparent Background

 "WinZip" - ZIP File Compression Tool

 "WinRAR" - RAR and ZIP File Compression Tool

 FTP Server, Client and Commands

 "FileZilla" - Free FTP Client and Server

 Web Server Log Files and Analysis Tool - "Analog"

 Spyware Adware Detection and Removal

 IE Addon Program Listing and Removal

Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal

 What Is Trojan Vundo

 Partial Removal of Trojan Vundo

 Detecting Trojan Vundo with McAfee VirusScan

 McAfee VirusScan and

 Instructions on Full Removal of Trojan Vundo

 Removing xxxxxxxx.dll Files Generated by Vundo

 What Is Vundo Related vtsts.dll

 Finding and Removing vtsts.dll Manually

Removing Trojan Vundo with FixVundo.exe from Symantec

 Removing Trojan Vundo with VundoFix.exe from Atribune.org

 Trojan and Malware "Puper" Description and Removal

 VSToolbar (VSAdd-in.dll) - Description and Removal

 Spybot - Spyware Blocker, Detection and Removal

 Setting Up and Using Crossover Cable Network

 Home Network Gateway - DSL Modem/Wireless Router

 Windows Task Manager - The System Performance Tool

 "tasklist" Command Line Tool to List Process Information

 "msconfig" - System Configuration Tool

 Configuring and Managing System Services

 Windows Registry Key and Value Management Tools

 Startup Programs Removal for Better System Performance

 Winsock - Windows Sockets API

 Java on Windows

 Glossary of Terms

 Outdated Tutorials

 References

 Full Version in PDF/ePUB