Trojan Vundo is part of a malware family that spreads as a polymorphic DLL file (ability to change itself with each mutation) and installs itself as a Browser Helper Object (BHO) without the users consent. Installed as a BHO, it redirect websites entered by the user into Google (and other search engines) to websites of its own choice.
When Trojan.Vundo.gen is executed, it performs the following activities:
It drops files on to the system at the following location:
It creates/modifies the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Random Name: "%WinDir%\system32\rundll32.exe %WinDir%\system32\[dropped DLL name].dll,[random character exported function]
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4