Detecting Trojan Vundo with McAfee VirusScan

This section provides a description of interesting behaviors of McAfee VirusScan reporting trojan Vundo infected files.

I decided to take a look at those suspicious DLL files on my own computer. The results are very interesting. I want to share with you here.

1. The first interesting note is on how McAfee VirusScan reacts to the DLL files. As I unzip the bho_200610.zip file that contains those suspicious DLL files, McAfee VirusScan On-Access Scan pops up a window telling that:

fcissfvg.dll   Vundo   Trojan  Deleted
lyssmlnb.dll   Vundo   Trojan  Deleted

Okay. This is nice. VirusScan is doing the job to pretect my system. But it only detected 2 out 3 DLL files. What happens to the third DLL file, yjsallam.dll? Did VirusScan fail to do the job or yjsallam.dll is not a Vundo infected file?

I believe VirusScan failed to do the detection job. But I can not prove it.

2. The second interesting note is on the impact left on my Windows system after McAfee VirusScan detected Trojan Vundo. When tried to shut down my Windows system after unzipping bho_200610.zip and closing McAfee VirusScan detection report window, my system, Windows XP, did close all applications normally. But it failed to shutdown completely with only the desktop background image on the screen. Nothing else is running.

I tried to push the power off button, but the system refused to shutdown. I have to remove the external power supply and remove the battery. That, of course, turned off the system completely.

Then I put the power supply back, and turned on the system. Windows started without any trouble. VirusScan did not report any issues. So may be it's normal for VirusScan to hold your shut down process to prevent triggering Vundo program again.

I did repeat 3 times of playing with McAfee VirusScan on those suspicious DLL files. I got exactly the same results:

Table of Contents

 About This Book

 Introduction to Microsoft Windows

 Introduction to Windows Explorer

 Introduction to Internet Explorer

 "Paint" Program and Computer Graphics

 GIMP - GNU Image Manipulation Program

 JPEG Image File Format Quality and Size

 GIF Image File Format and Transparent Background

 "WinZip" - ZIP File Compression Tool

 "WinRAR" - RAR and ZIP File Compression Tool

 FTP Server, Client and Commands

 "FileZilla" - Free FTP Client and Server

 Web Server Log Files and Analysis Tool - "Analog"

 Spyware Adware Detection and Removal

 IE Addon Program Listing and Removal

Vundo (VirtuMonde/VirtuMundo) - vtsts.dll Removal

 What Is Trojan Vundo?

 Partial Removal of Trojan Vundo

Detecting Trojan Vundo with McAfee VirusScan

 McAfee VirusScan and

 Instructions on Full Removal of Trojan Vundo

 Removing xxxxxxxx.dll Files Generated by Vundo

 What Is Vundo Related vtsts.dll?

 Finding and Removing vtsts.dll Manually

 Removing Trojan Vundo with FixVundo.exe from Symantec

 Removing Trojan Vundo with VundoFix.exe from Atribune.org

 Trojan and Malware "Puper" Description and Removal

 VSToolbar (VSAdd-in.dll) - Description and Removal

 Spybot - Spyware Blocker, Detection and Removal

 Setting Up and Using Crossover Cable Network

 Home Network Gateway - DSL Modem/Wireless Router

 Windows Task Manager - The System Performance Tool

 "tasklist" Command Line Tool to List Process Information

 "msconfig" - System Configuration Tool

 Configuring and Managing System Services

 Windows Registry Key and Value Management Tools

 Startup Programs Removal for Better System Performance

 Winsock - Windows Sockets API

 Java on Windows

 Glossary of Terms

 Outdated Tutorials

 References

 PDF Printing Version