Virus possible BVD32.exe

Posted on 2009-04-30
Last Modified: 2013-12-09
I have an  issue on a couple of networks with the home directories of users getting a file put into them called bvd32.exe and when the users log in to infected machines it comes up with 2 error windows (dos windows) saying that ntvdm running bvd32.exe has had an error it asks you to ignore or close. has anybody else come across this file and how it infects checking virustotal none of the leading antivirus manufacturers seem to pick it up

Question by:asrats
    LVL 47

    Expert Comment

    Download and run both of these tools and show us the logfiles. If they won't run, then redownload and rename before saving to your desktop.

    1.  Download Malwarebytes' Anti-Malware to your desktop, check for the tool's Updates before running a scan.

    2.  Please download ComboFix by sUBs:
    You must download it to and run it from your Desktop
    Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
    Re-enable all the programs that were disabled during the running of ComboFix..

    Do not mouse-click combofix's window while it is running. That may cause it to stall.
    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:

    Author Comment

    i ended up reinstaling machine thanks for assistance

    they didnt have many programs on it

    Author Comment

    running combofix on machine then manualy deleting files fixed issue on another machine
    LVL 47

    Accepted Solution

    Reformatting and reinstalling is always the safest solution and with not so many programs to put back that's the best solution.
    <<<"running combofix on machine then manualy deleting files fixed issue on another machine">>>

    Combofix has a script function to delete bad files that weren't deleted in the first run that's why we always ask to look at the CF log to make sure it's clean.
    Glad to know the issue on another pc is fixed.

    To uninstall Combofix:
    Go to Start > Run and 'copy and paste' next command in the field:

    ComboFix /u

    You can then close this question please.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Maximize Your Threat Intelligence Reporting

    Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

    Some of the most commonly posted questions in the "Virus & Malware" Zones are related to the family of rogue malware with the date "2012" somewhere in the title. Examples: XP Antispyware 2012 XP Antivirus 2012 XP Security 2012   XP Home Sec…
    There are many reasons malware will stay around and continue to grow as a business.  The biggest reason is the expanding customer base.  More than 40% of people who are infected with ransomware, pay the ransom.  That makes ransomware a multi-million…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    This video discusses moving either the default database or any database to a new volume.

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    10 Experts available now in Live!

    Get 1:1 Help Now