Home Malware Programs Trojans Vundo.b

Vundo.b

Posted: March 28, 2006

Vundo.b is a variant of the Vundo trojan. The spyware is designed to show large amount of unsolicited commercial pop-up advertisements. It may also contact predetermined remote web servers, silently download and execute potentially harmful files. Vundo.b automatically runs on every Windows startup.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonNotify[filename]
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44

Related Posts

One Comment

  • Bev says:

    I ran a scan from STOPZILLA & it showed i had (4) ' Gen Trojan Installer C' and (2) 'Vundo W'. My McAfee won't scan & didn't detect these previously. I noticed you have a Vundo B, not W. What do I do to rid these?

Loading...