Click on screenshot to zoom
Danger level 10
Type: Trojans
Common infection symptoms:
  • Changes background
  • Connects to the internet without permission
  • Shows commercial adverts
  • Normal system programs crash immediatelly
  • Strange toolbar installed without Your permission
  • Slow internet connection
  • System crashes
  • Cant change my homepage
  • Annoying Pop-up's
  • Slow Computer
Other mutations known as:

Vundo

Vundo is a big family of Trojans which are designed to deliver ‘out of context’ pop-up advertisements. They are also able to download and execute arbitrary files. It is possible to get infected with Vundo via peer-to-peer file sharing, spam email; drive-by downloads and so on. This presupposes that the user must be cautious of what kind of files he or she downloads or saves into personal computer, because the Trojan can be hiding anywhere.

As far as the functions of Vundo are concerned, not only does it display annoying pop-up advertisements on the affected computer, it can also inject commercial ads into the search results. Vundo shows all kinds of pop-ups which include these fake scan results, bleeping in order to scare the user to think that the computer has been compromised and then click on the “further information” button. Needless to say, that the advertisements generated by Vundo promote websites which offer usually malicious programs, which promise erase non-existent viruses from the computer. And of course, in order to use these programs, one would have to buy it.

So it is obvious that Vundo is a part of the rogue antispyware distribution and promotion system. Not to mention that it also advertises adult web sites and services. Therefore Vundo must be deleted from the system, because it is an annoying parasite which can lead to an even more serious infection. This Trojan tries hard to remain the affected computer by lowering security settings and preventing the user to access certain sites. It also disables certain system software, and in some cases it can go as far as trying to disable antivirus programs.

Due to the fact that Vundo is good at hiding itself and resisting the interrogation of security products, the average user might find it very hard to remove Vundo on his own. In such case the user can download an up-to-date malware removal program, which will intercept and delete Vundo efficiently for him.

Download Spyware Removal Tool to Remove* Vundo
  • Quick & tested solution for Vundo removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Vundo

Files associated with Vundo infection:

ljJYPfdD.dll
bawtygwr.dll
vthykqmd.dll
mcdgwo.dll
geBtQgEx.dll
mlJArppO.dll
xzsayk.dll
nxljosse.dll
gawkjesp.dll
nciruh.dll
nvwjphjb.dll
hxbdht.dll
yjhwqywj.dll
khfFuVoN.dll
byXOgeBt.dll
vtUkjJAS.dll
fcccyVPi.dll
vgifofek.dll
qoMdCuSI.dll
ljJAQKeC.dll
iifdddEX.dll
ljJCrPIB.dll
ddcARhhG.dll
bbqcfsxm.dll
abvwmbgb.dll
usjmyb.dll
cjdfyh.dll
ddcYsRhh.dll
xfedlxrj.dll
vtUlJyWn.dll
tuvUOGvs.dll
byXroNET.dll
qoMfeedC.dll
iifgDVNG.dll
geBtQihF.dll
ljJBrOFV.dll
lfuhuuwf.dll
ckds16.dll
geBtQkLE.dll
wvUoppPh.dll
qqkdgkie.dll
cbXRHbab.dll
efcDVmLb.dll
mws29854.dll
yjrhhukn.dll
hgGYoPGx.dll
tuvSihIy.dll
xxyvuuro.dll
uvwvjvgk.dll
rlawcyxm.dll
khfFyVPj.dll
efcCspPg.dll
file[2].exe
opnKecCv.dll
geBuUMef.dll
khfghhIA.dll
iifgfCsP.dll
tuVPgdDW.dll
qoMfEusT.dll
qvmzxdoc.dll
10002.exe
mqmnhhrd.dll
xh-codec.v.1.189[1].exe
jkkIBTNE.dll
iifecbYo.dll
rqRiGyvw.dll
wvUlkHaX.dll
cqaihphf.dll
hgGaATJa.dll
mlJYOeby.dll
update.1.014[1].exe
file[1].exe
ljJARjii.dll
awtussPi.dll
geBtUoLd.dll
sywagp.dll
dsnrhz.dll
scan[1].exe
1696513598.exe
ssqnmNhI.dll
ljJYRJDw.dll
jkkIyYSi.dll
egesewvs.dll
cbXqpoMF.dll
srqss.ini2
srqss.ini
srqss.bak2
srqss.bak1
yayyyxw.dll
yayxwxx.dll
yayvtsp.dll
xxyywxw.dll
xxyaywu.dll
xxyawvw.dll
xleshega.dll
wvuvvut.dll
wvusqrr.dll
wvusqqq.dll
wvusqqn.dll
wvurrro.dll
vtuutrq.dll
urqqpom.dll
urqpoom.dll
urqopqn.dll
urqnoml.dll
urqnklj.dll
tuvttsq.dll
tuvtsqq.dll
tuvssss.dll
tuvsspp.dll
ssqrs.dll
ssqrrqr.dll
ssqrpno.dll
ssqqrop.dll
ssqpppm.dll
ssqomkj.dll
ssqnnmn.dll
rqrolkk.dll
qomlljh.dll
qomlkjj.dll
qomkjkj.dll
pmnljgg.dll
pmnkhgf.dll
opnomll.dll
opnklif.dll
nnnonnk.dll
nnnmjig.dll
nnnllji.dll
nnnklml.dll
mljkiji.dll
mljghfe.dll
mljgedd.dll
ljjkigd.dll
ljjjhge.dll
ljjhhig.dll
khffcdd.dll
khfefed.dll
khfdaab.dll
jkklmli.dll
jkkkigf.dll
jkkhheb.dll
iifddec.dll
iifddaw.dll
iifccbc.dll
hgghfda.dll
hggggfc.dll
hggeeff.dll
hggebxw.dll
hggdbyw.dll
gebxxxx.dll
gebbbby.dll
fccaxyy.dll
efcyvss.dll
efccbxv.dll
efcbcyy.dll
efcayvs.dll
ddcyvvw.dll
cbxvvww.dll
cbxvsrp.dll
byxxwtq.dll
byxvvsp.dll
bqtsmphi.dll
awturop.dll
awttrpo.dll
awtstqn.dll
aocreofm.dll
agtcesdo.exe
vtsqo.dll

Vundo DLL's to remove:

ljJYPfdD.dll
bawtygwr.dll
vthykqmd.dll
mcdgwo.dll
geBtQgEx.dll
mlJArppO.dll
xzsayk.dll
nxljosse.dll
gawkjesp.dll
nciruh.dll
nvwjphjb.dll
hxbdht.dll
yjhwqywj.dll
khfFuVoN.dll
byXOgeBt.dll
vtUkjJAS.dll
fcccyVPi.dll
vgifofek.dll
qoMdCuSI.dll
ljJAQKeC.dll
abvwmbgb.dll
usjmyb.dll
cjdfyh.dll
ddcYsRhh.dll
xfedlxrj.dll
vtUlJyWn.dll
tuvUOGvs.dll
byXroNET.dll
qoMfeedC.dll
iifgDVNG.dll
geBtQihF.dll
ljJBrOFV.dll
lfuhuuwf.dll
ckds16.dll
geBtQkLE.dll
wvUoppPh.dll
qqkdgkie.dll
cbXRHbab.dll
efcDVmLb.dll
mws29854.dll
yjrhhukn.dll
hgGYoPGx.dll
tuvSihIy.dll
xxyvuuro.dll
uvwvjvgk.dll
rlawcyxm.dll
khfFyVPj.dll
efcCspPg.dll
opnKecCv.dll
geBuUMef.dll
khfghhIA.dll
iifgfCsP.dll
tuVPgdDW.dll
qoMfEusT.dll
qvmzxdoc.dll
mqmnhhrd.dll
jkkIBTNE.dll
iifecbYo.dll
rqRiGyvw.dll
wvUlkHaX.dll
cqaihphf.dll
hgGaATJa.dll
mlJYOeby.dll
ljJARjii.dll
awtussPi.dll
geBtUoLd.dll
sywagp.dll
dsnrhz.dll
ssqnmNhI.dll
ljJYRJDw.dll
jkkIyYSi.dll
egesewvs.dll
cbXqpoMF.dll
yayyyxw.dll
yayxwxx.dll
yayvtsp.dll
xxyywxw.dll
xxyaywu.dll
xxyawvw.dll
xleshega.dll
wvuvvut.dll
wvusqrr.dll
wvusqqq.dll
wvusqqn.dll
wvurrro.dll
vtuutrq.dll
urqqpom.dll
urqpoom.dll
urqopqn.dll
urqnoml.dll
urqnklj.dll
tuvttsq.dll
tuvtsqq.dll
tuvssss.dll
tuvsspp.dll
ssqrs.dll
ssqrrqr.dll
ssqrpno.dll
ssqqrop.dll
ssqpppm.dll
ssqomkj.dll
ssqnnmn.dll
rqrolkk.dll
qomlljh.dll
qomlkjj.dll
qomkjkj.dll
pmnljgg.dll
pmnkhgf.dll
opnomll.dll
opnklif.dll
nnnonnk.dll
nnnmjig.dll
nnnllji.dll
nnnklml.dll
mljkiji.dll
mljghfe.dll
mljgedd.dll
ljjkigd.dll
ljjjhge.dll
ljjhhig.dll
khffcdd.dll
khfefed.dll
khfdaab.dll
jkklmli.dll
jkkkigf.dll
jkkhheb.dll
iifddec.dll
iifddaw.dll
iifccbc.dll
hgghfda.dll
hggggfc.dll
hggeeff.dll
hggebxw.dll
hggdbyw.dll
gebxxxx.dll
gebbbby.dll
fccaxyy.dll
efcyvss.dll
efccbxv.dll
efcbcyy.dll
efcayvs.dll
ddcyvvw.dll
cbxvvww.dll
cbxvsrp.dll
byxxwtq.dll
byxvvsp.dll
bqtsmphi.dll
awturop.dll
awttrpo.dll
awtstqn.dll
aocreofm.dll
vtsqo.dll

Vundo processes to kill:

file[2].exe
10002.exe
xh-codec.v.1.189[1].exe
update.1.014[1].exe
file[1].exe
scan[1].exe
1696513598.exe
agtcesdo.exe

Remove Vundo registry entries:

44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44
HKEY_LOCAL_MACHINE SOFTWAREClassesCLSID{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows NT CurrentVersionWinlogonNotify[filename]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonNotify[filename]
Microsoft\Active Setup\Installed Components\{A744F16C-B2D5-4138-81A2-085CDFCDE83A}
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtussPi
MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\ddcYsRhh
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBuUMef
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ifadlz
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifecbYo
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifgfCsP
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfFuVoN
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljJBrOFV
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljJYRJDw
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljJYRJDwObjects\{32A75D52-5C2C-4D52-8107-1239F8F791E0}
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mlJYOeby
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qoMdCuSI
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvSihIy
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects {869B20A6-AADA-477D-BE23-68A966B1183D}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09390640-45B8-4A78-A294-8887AA1BFB79}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17D81C1E-8AB5-488D-8076-F1B68A4F46BF}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1B5FEF9D-92A7-42DF-A6A1-3BC7EF9904A5}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CF662BF-4AFD-4778-8306-1F0EB8284EBB}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1D3E0364-A660-41C6-B487-B39791ED2344}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3258EFEB-5E44-4441-9A3E-676E6671A9E0}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32A75D52-5C2C-4D52-8107-1239F8F791E0}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32C620D6-CC10-4e6a-9715-BACACD5B0E61}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{40B725ED-5416-45C8-93CF-3139FF5B7BCE}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4777353E-D7D1-4D47-9300-9D790FEBE87B}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48F2A76C-BCC4-4D15-97AC-2C78BC84CB45}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4910234A-B457-4278-90D2-0CE778675E25}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F90619-EDBB-4C1A-A7D6-924D3C1BFD19}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B566B65-9908-455A-BD18-E0A95232C1D3}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E068E05-74AE-42D5-AA9D-694A709750AB}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73259091-9574-4ED8-A40F-7F65AFC28634}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{76427AE7-326F-46D9-BFEF-82A7B4EA0F04}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{76CFB752-E1B5-45E5-871F-E696B997FFB1}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F2F91F2-6B8F-42F0-8A0C-11F19978EF52}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8BFBD67C-3AF5-4954-A8F7-B15C96B1086B}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91B0A470-7C46-3176-933C-A2CBDE1AA86A}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9BEA3041-ED41-47D9-80C1-6656905B956C}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A14FB995-D8AC-494B-A6D3-ADC04028F281}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A9DBBE9E-E937-4A1D-94CC-20C8CE0135D5}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AD2605AB-4BFF-4A71-9723-4E6D914322E7}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AD91194F-AB20-432C-9508-E8BA30DB5427}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1AD2294-FA98-4F5D-BB37-3D6358E3654E}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9B5B133-7A48-4E14-A432-0E725005E6D3}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C16CDB5C-2468-4116-AD60-868CA1
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C8EDE367-6748-4AA0-AED9-DBD3853413C5}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9188A6B-81ED-4BD8-8A80-1C798B1ED7D0}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D278AB78-308B-472C-BEDD-5078B3F29ECB}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{db5a474a-12a0-4d26-a1fc-a7ea8ef94edc}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F1C5B241-BFBE-4CFC-99A4-76823ADF23F6}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F293D4EB-7EF6-4991-BFA1-C7E3CE125D8E}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5F015D8-AC73-4AB8-A99F-503479159097}
Microsoft\Windows\CurrentVersion\Ext\Stats\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
Microsoft\Windows\CurrentVersion\Run\BM9376ab5b
S
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{1CF662BF-4AFD-4778-8306-1F0EB8284EBB}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{48F2A76C-BCC4-4D15-97AC-2C78BC84CB45}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4910234A-B457-4278-90D2-0CE778675E25}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{A14FB995-D8AC-494B-A6D3-ADC04028F281}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{A9DBBE9E-E937-4A1D-94CC-20C8CE0135D5}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{F1C5B241-BFBE-4CFC-99A4-76823ADF23F6}
{1CF662BF-4AFD-4778-8306-1F0EB8284EBB}
{32A75D52-5C2C-4D52-8107-1239F8F791E0}
{32C620D6-CC10-4e6a-9715-BACACD5B0E61}
{40B725ED-5416-45C8-93CF-3139FF5B7BCE}
{48F2A76C-BCC4-4D15-97AC-2C78BC84CB45}
{4910234A-B457-4278-90D2-0CE778675E25}
{68F90619-EDBB-4C1A-A7D6-924D3C1BFD19}
{6B566B65-9908-455A-BD18-E0A95232C1D3}
{9BEA3041-ED41-47D9-80C1-6656905B956C}
{A14FB995-D8AC-494B-A6D3-ADC04028F281}
{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}
{A744F16C-B2D5-4138-81A2-085CDFCDE83A}
{A9DBBE9E-E937-4A1D-94CC-20C8CE0135D5}
{AD2605AB-4BFF-4A71-9723-4E6D914322E7}
{AD91194F-AB20-432C-9508-E8BA30DB5427}
{C8EDE367-6748-4AA0-AED9-DBD3853413C5}
{C9188A6B-81ED-4BD8-8A80-1C798B1ED7D0}
{D278AB78-308B-472C-BEDD-5078B3F29ECB}
{F1C5B241-BFBE-4CFC-99A4-76823ADF23F6}
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.