Threat Database Trojans Trojan.Win32/Vundo.gen!X

Trojan.Win32/Vundo.gen!X

By GoldSparrow in Trojans

So your browser has a mind of its own and is redirecting your search and shooting off ridiculous error messages? I know you may hear random music playing, music you didn't initiate, but no, your PC has not come alive. This mischief is most likely the doing of a nasty family of Trojans.

Callously known as the rootkit gang, Trojan.Win32/Vundo.gen!X is a family of Trojans who love to inject malicious code into your PC memory, so hackers can remotely do whatever they want. Stop the madness before it goes too far!

PC users are being tortured by the rootkit gang, Trojan.Win32/Vundo.gen!X, who has been reported randomly redirecting persons to malicious or undesired websites. Some reported web pages mentioning 'Mevio' and some PC users experienced an Internet Explorer (IE) sidebar that contained paid links. Many have complained about getting IE error message stating "An error has occurred in the script on this page."

When one PC user was forcibly redirected and checked the URL, it listed this:

www2a.glam.com/mobile/detect.act?affiliateId=38198522 ß (Do not click! Ity leads to malware)

So What Is Going On?

The demon possession you are experiencing may have deceptively come attached to a recent download of an infected file or plug-in. It also is possible the nasty Trojan was left over after a recent sweep or removal of a rogue security program such as Windows Recovery or Windows Repair, to name only a few.

Trojan.Win32/Vundo.gen!X hides in the 'root' of your system and is known to embed files into the kernel of your operating system. From there, Trojan.Win32/Vundo.gen!X may modify the OS itself and intercept calls to fool your anti-malware and remain undetected.

Trojans like Trojan.Win32/Vundo.gen!X are silent killers, and because they contain backdoor capabilities, they may lay dormant until called or triggered by the remote controller. Damaged caused by Trojans are progressive, and although they are not known for immediate destruction like a virus, or for spreading quickly like a worm, they are the worst kind of enemy – since they open the gateway for hackers to steal your keystrokes (online or offline) and secretly control your PC. Data collected (or stolen) is usually transferred at the next boot and/or Internet connection.

Signs You Have Been Infected by Trojan.Win32/Vundo.gen!X

  • Browser redirects you to malicious or unwanted web pages
  • Home page has been changed
  • Random playing of music from malicious advertisements or banners
  • Repeated pop-up and script errors
  • User drive and all file contents (documents, pictures, music, etc.) may appear to have disappeared – Trojan pain-in-the-butt hid them, so don’t panic

Can You Manually Remove Trojan.Win32/Vundo.gen!X?

We could tell you no, and some gung-ho PC user will disagree and tell you they had no problems finding and deleting the file, but again, that is the problem. Trojan.Win32/Vundo.gen!X was built to hide and trick you into believing Trojan.Win32/Vundo.gen!X is gone. Most anti-virus or anti-spyware programs are not equipped to detect and remove Trojan.Win32/Vundo.gen!X, so you should not be dismayed when you learn that your manual efforts failed.

Rootkits bury themselves deeper than viruses and may go as deep as to infect your BIOS, which makes them that much harder to remove. There is but one problem, time is the essence. As we've mentioned, Trojan.Win32/Vundo.gen!X has the ability to open up the back door of your PC to hackers and when called, Trojan keylogger will steal all your vital data, i.e. passwords, usernames, bank or credit card information, etc. So, as you can see, Trojan.Win32/Vundo.gen!X poses a great threat to your data and your PC and needs to be totally wiped cleaned or removed immediately!

Using a combination of anti-rooftkit software and a solid anti-malware program should do the trick, but the longer or deeper Trojan.Win32/Vundo.gen!X has been allowed to stay, you may end up needing to rebuild your entire system to ensure Trojan.Win32/Vundo.gen!X is gone.

Registry Details

Trojan.Win32/Vundo.gen!X may create the following registry entry or registry entries:
HKEY_CLASSES_ROOT\CLSID\{8109AF33-6949-4833-8881-43DCC232B7B2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce*[FILENAME]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ATLEvents.ATLEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Active State
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce*WinLogon
HKEY_CLASSES_ROOT\CLSID\{2316230A-C89C-4BCC-95C2-66659AC7A775}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8109AF33-6949-4833-8881-43DCC232B7B2}

Trending

Most Viewed

Loading...