How to Remove the Vundo Trojan Gen D
Vundo Trojan Gen D is a Trojan from the Vundo family of Trojans. This is a common family of Trojans that is spread through e-mail. Once your computer becomes infected with a Trojan from the Vundo family, you will notice a reduction in the available memory of your computer, an increase in popup ads, and a slowing of your computer processing speed. Fortunately, these Trojans can be removed by following these easy steps.
Instructions
-
Remove Infected Processes
-
1
Press "CTRL + ALT + Delete".
-
2
Click on "Task Manager," then click on the "Processes" tab.
-
-
3
Scroll down the list of processes and find "vzbb.dll."
-
4
Right-click on "vzbb.dll," and select "End Process."
Remove Infected DLL Files
-
5
Click on the "Start" menu, then click "Run."
-
6
Type "cmd" into the open box and click "OK."
-
7
Type "regsvr32 /u vzbb.dll" and press the "Enter" key.
Remove Infected Registry Values
-
8
Click on the "Start" menu, then click "Run."
-
9
Type "regedit" in the open box and click "OK."
-
10
Find the following files in the left pane and delete them. To delete a file, simply right-click on it and select "Modify," and then "Delete."
"HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainActiveState
02F96FB7-8AF6-439B-B7BA-2F952F9E4800"
"HKEY_LOCAL_MACHINESOFTWAREClassesATLEvents.ATLEvents.1"
"HKEY_LOCAL_MACHINESOFTWAREClassesATLEvents.ATLEvents
8109AF33-6949-4833-8881-43DCC232B7B2
2316230A-C89C-4BCC-95C2-66659AC7A775"
"HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce*[filename]"
"HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainActive State "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOnce*WinLogon"
"HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{8109AF33-6949-4833-8881-43DCC232B7B2}"
"HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{2316230A-C89C-4BCC-95C2-66659AC7A775}"
"HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}"
"HKEY_LOCAL_MACHINE SOFTWAREClassesCLSID{02F96FB7-8AF6-439B-B7BA-2F952F9E4800}"
"HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents.1"
"HKEY_LOCAL_MACHINE SOFTWAREClassesATLEvents.ATLEvents"
"HKEY_CLASSES_ROOTCLSID{8109AF33-6949-4833-8881-43DCC232B7B2}"
"HKEY_CLASSES_ROOTCLSID{2316230A-C89C-4BCC-95C2-66659AC7A775}"
"HKEY_LOCAL_MACHINE SoftwareMicrosoftWindows CurrentVersionRunOnce*[filename]"
"HKEY_CURRENT_USER SoftwareMicrosoftWindows CurrentVersionRunOnce*WinLogon"
-
1
Tips & Warnings
In addition to following the aforementioned steps, it is important to purchase and run antivirus software. This will remove any infected files you may have missed, as well as help prevent future Trojans from infecting your computer.
References
- Photo Credit frustrated business man image by Melking from Fotolia.com