Malware City has come up with a removal guide for the latest versions of Vundo. It usually copies itself into %windows%system32 with a 5 to 7 characters long random name, and executes at windows startup. We have used two freely available applications: AutoRuns and process explorer. Before starting our guide, please download them from the links provided. Follow these steps: Locate a dll file with random name residing in %windows%.system32 (often also without Description and Publisher)”]
Source: https://www.bitdefender.com/blog/hotforsecurity/how-to-remove-trojan-vundo/