Windows Tutorials - Herong's Tutorial Notes
Dr. Herong Yang, Version 4.20

Trojan and Adware - Vundo (vtsts.dll) Removal

Part:   1  2  3  4  5  6 

Windows Tutorials - Herong's Notes © 2006 Dr. Herong Yang

Adware - VSAdd-in.dll and Removal

Trojan and Adware - Vundo

Controlling IE Addons

Removing Spyware

Web Log Analysis

Paint - Graphics Tool

WinRAR - RAR Compression Tool

FTP Server and Client

Crossover Cable Network

... Table of Contents

(Continued from previous part...)

Trying to Remove Trojan Vundo with FixVundo.exe from Symantec

As I mentioned in my previous note, my first choice was to use the tool and instruction provided by Symantec at: http://www.symantec.com/security_response/writeup.jsp?docid=2004-112210-3747-99

1. Downloaded FixVundo.exe from http://securityresponse.symantec.com/avcenter/FixVundo.exe:

11/04/2006  08:51 AM           166,064 FixVundo.exe
File properties: 
   File version: 1.5.0.0
   Copyright: Copyright(C) 2004 Symantec Corporation

2. Closed all applications and disconnect from the Internet.

3. Disabled Windows System Restore function to avoid Trojan Vundo hiding in the restore area:

Click Start >> My Computer
Right-mouse click and select Properties. Properties dialog box displays.
Click System Restore tab
Check "Turn of System Restore" checkbox
Click Apply

4. Ran FixVundo.exe and clicked the Start button. It started to scan the entire hard disk. This took about 20 minutes. Surprisingly, FixVundo reported no Vundo infections.

But when I looked at the log file, FixVundo.log, I saw this:

Symantec Trojan.Vundo Removal Tool 1.5.0

The process "explorer.exe" contained a viral thread (00000444). 
   The thread was terminated.

The process "explorer.exe" contained a viral thread (00000450). 
   The thread was terminated.

Trojan.Vundo has not been found on your computer.

Conclusion: The latest version of FixVundo 1.5.0 from Symantec was not able to detect the Trojan Vundo files. But it did find some issues in the running explorer.exe process.

Removing Trojan Vundo with VundoFix.exe from Atribune.org

My first choice failed. So I had to try my second choice: VundoFix.exe and instruction provided by Atribune.org at http://www.atribune.org/content/view/24/2/.

1. Downloaded VundoFix.exe from http://www.atribune.org/ccount/click.php?id=4

11/04/2006  09:56 AM            88,576 VundoFix.exe
File properties: 
   File version: 6.2.0.6
   Copyright: (C) atribune.org

(Continued on next part...)

Part:   1  2  3  4  5  6 

Dr. Herong Yang, updated in 2006
Windows Tutorials - Herong's Tutorial Notes - Trojan and Adware - Vundo (vtsts.dll) Removal