Vundo trojan
From Wikipedia, the free encyclopedia
The Vundo trojan is a trojan horse that may cause popups advertising rogue antispyware programs. It infects victims' computers by exploiting a vulnerability in Sun Java 1.4 and earlier versions. Many of the popups advertise a program called Sysprotect
Contents |
[edit] Typical dialog
Below is a screenshot of the dialog box that appears upon infection.
The English language version of the message reads:
"NOTICE: If your computer has errors in the registry database or filesystem, it could cause unpredictable or erratic behavior, freezes and crashes. Fixing these errors can increase your computer's performance and prevent data loss.
Would you like to install SysProtect for free? (Recommended)"
On Windows system other than English, user may see a "localised" message in their native language.
Removing outdated versions of Sun Java prevents this infection. A tool called VundoFix is commonly used for removing this infection.
[edit] Removal
Many tools and programs have been written to remove Vundo, although the trojan's authors often release new versions. Vundo creates a DLL file in the Windows system directory and writes registry entries causing Windows to inject the file into winlogon.exe.
[edit] See also
- HijackThis - can detect some Vundo variants
- VundoFix - Tool for removing Vundo infections
- SysProtectRemover - Tool for removing SysProtect specifically by the maker of Vundofix.
- WinFixer - A similar program to SysProtect