bndmod.exe - can't get rid of it

Discussion in 'malware problems & news' started by alanm333, Nov 6, 2005.

Thread Status:
Not open for further replies.
  1. alanm333

    alanm333 Registered Member

    Joined:
    Oct 20, 2003
    Posts:
    25
    Hi
    This one is really difficult to shift! Can anyone help please?
    I run XP Pro SP1 and have tried S&D 1.2, adaware 6.181, Xoftspy, and ewido all in safe mode, without effecting it. I run McAfee Virus scan and my windows firewall is always on.
    Any advice would be greatly appreciated. Thanks
    I forgot to say that it is picked up by McAfee every time I start IE 6 and is auto deleted, but IE tries to close, and when I reopen - its back and is again auto deleted.
     
  2. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Could u post the full path of the file?


    snowbound
     
  3. alanm333

    alanm333 Registered Member

    Joined:
    Oct 20, 2003
    Posts:
    25
    Hi
    C:\WINDOWS\system32\bndmod.exe
    ( it doesn't come up every time actually - sometimes I can get a few hours before it returns, but when it's active I can't open IE withoiut the McAfee message plus the IE message telling me to close because of an error - 'send or don't send' to Microsoft
     
  4. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
  5. Beef

    Beef Guest

  6. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    If i had that problem i would post a HJT log(not here at Wilders though) ;) :D

    It's a tool i rely on when i have any suspicion of malware on my comp.


    snowbound
     
  7. Beef

    Beef Guest

    Snowbound

    Thank you for checking that out......it appeared as much to me as well but felt you are in a better position to suggest it since you have more experience in that area. Thanks
     
Loading...
Thread Status:
Not open for further replies.