Windows Tutorials - Herong's Tutorial Examples - v5.62, by Dr. Herong Yang
Removing Trojan Vundo with FixVundo.exe from Symantec
This section provides a tutorial example of how to remove trojan Vundo with FixVundo.exe from Symantec.
As I mentioned in my previous tutorial, my first choice was to use the tool and instruction provided by Symantec at: http://www.symantec.com/security_response/writeup.jsp?docid=2004-112210-3747-99
1. Downloaded FixVundo.exe from http://securityresponse.symantec.com/avcenter/FixVundo.exe:
11/04/2006 08:51 AM 166,064 FixVundo.exe File properties: File version: 1.5.0.0 Copyright: Copyright(C) 2004 Symantec Corporation
2. Closed all applications and disconnect from the Internet.
3. Disabled Windows System Restore function to avoid Trojan Vundo hiding in the restore area:
Click Start >> My Computer Right-mouse click and select Properties. Properties dialog box displays. Click System Restore tab Check "Turn of System Restore" checkbox Click Apply
4. Ran FixVundo.exe and clicked the Start button. It started to scan the entire hard disk. This took about 20 minutes. Surprisingly, FixVundo reported no Vundo infections.
But when I looked at the log file, FixVundo.log, I saw this:
Symantec Trojan.Vundo Removal Tool 1.5.0 The process "explorer.exe" contained a viral thread (00000444). The thread was terminated. The process "explorer.exe" contained a viral thread (00000450). The thread was terminated. Trojan.Vundo has not been found on your computer.
Conclusion: The latest version of FixVundo 1.5.0 from Symantec was not able to detect the Trojan Vundo files. But it did find some issues in the running explorer.exe process.
Table of Contents
Introduction to Microsoft Windows
Introduction to Windows Explorer
Introduction to Internet Explorer
"Paint" Program and Computer Graphics
GIMP - GNU Image Manipulation Program
JPEG Image File Format Quality and Size
GIF Image File Format and Transparent Background
"WinZip" - ZIP File Compression Tool
"WinRAR" - RAR and ZIP File Compression Tool
FTP Server, Client and Commands
"FileZilla" - Free FTP Client and Server
Web Server Log Files and Analysis Tool - "Analog"
Spyware Adware Detection and Removal
IE Addon Program Listing and Removal
►Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal
Partial Removal of Trojan Vundo
Detecting Trojan Vundo with McAfee VirusScan
Instructions on Full Removal of Trojan Vundo
Removing xxxxxxxx.dll Files Generated by Vundo
What Is Vundo Related vtsts.dll
Finding and Removing vtsts.dll Manually
►Removing Trojan Vundo with FixVundo.exe from Symantec
Removing Trojan Vundo with VundoFix.exe from Atribune.org
Trojan and Malware "Puper" Description and Removal
VSToolbar (VSAdd-in.dll) - Description and Removal
Spybot - Spyware Blocker, Detection and Removal
Setting Up and Using Crossover Cable Network
Home Network Gateway - DSL Modem/Wireless Router
Windows Task Manager - The System Performance Tool
"tasklist" Command Line Tool to List Process Information
"msconfig" - System Configuration Tool
Configuring and Managing System Services
Windows Registry Key and Value Management Tools