Windows Tutorials - Herong's Tutorial Notes
Dr. Herong Yang, Version 4.20

Trojan and Adware - Vundo (VirtuMonde/VirtuMundo)

Part:   1  2  3  4 

Windows Tutorials - Herong's Notes © 2006 Dr. Herong Yang

Adware - VSAdd-in.dll and Removal

Trojan and Adware - Vundo

Controlling IE Addons

Removing Spyware

Web Log Analysis

Paint - Graphics Tool

WinRAR - RAR Compression Tool

FTP Server and Client

Crossover Cable Network

... Table of Contents

This chapter describes:

  • What Is Trojan Vundo?
  • Experience of Removing Trojan Vundo
  • Detecting Trojan Vundo with McAfee VirusScan
  • Full Removal of Trojan Vundo
  • What Is VirusScan?

What Is Trojan Vundo?

Vundo is a malicious program for Windows system. Here are some short descriptions of Vundo I found on the Internet:

1. From www.spynomore.com/articles/vundo-trojan-specifics-and-removal.php:

Vundo (also known as VirtuMonde and VirtuMundo) is a malicious
software application that combines both adware and trojan 
characteristics.

Vundo is wide spread today and is probably one of the hardest programs
to get rid of. Once installed, Vundo downloads and displays pop-up
advertisements that often promote questionable computer-enhancement 
programs or fake anti-virus or anti-spyware utilities. Lately, Vundo
has been advertising several rogue programs called WinFixer2005, 
WinAntiVirus Pro 2006, WinAntiSpyware and RazeSpyware.

2. From vil.nai.com/vil/content/v_127690.htm:

This is a trojan detection. Unlike viruses, trojans do not 
self-replicate. They are spread manually, often under the premise that
they are beneficial or wanted. The most common installation methods 
involve system or security exploitation, and unsuspecting users 
manually executing unknown programs. Distribution channels include 
email, malicious or hacked web pages, Internet Relay Chat (IRC), 
peer-to-peer networks, etc.

3. From en.wikipedia.org/wiki/Vundo:

The Vundo trojan is a trojan horse that may cause popups advertising
rogue antispyware programs. It infects victims' computers by 
exploiting a vulnerability in Sun Java 1.4 and earlier versions. 
Many of the popups advertise a program called Sysprotect.

But I don't think any of the above descriptions is accurate. Not long ago, I was asked by a friend of mine to look at his Vundo infected computer. I want to share some notes with you that may help you understand Trojan Vundo better.

(Continued on next part...)

Part:   1  2  3  4 

Dr. Herong Yang, updated in 2006
Windows Tutorials - Herong's Tutorial Notes - Trojan and Adware - Vundo (VirtuMonde/VirtuMundo)