Hello. I run Panda Software for my antivirus software. When completing a recent scan Panda found the Trojan Mitglieder.BO virus. It said notified but not deleted or quarantined. Does anyone know how to get rid of this virus? It is slowing my system down so much it's ridiculous. I also have a problem with NTVDM.EXE. It keeps opening by itself and using 100% of the processor freezing the system. Any ideas on getting rid of this. The only way I can stop it is by going into task manager and closing the process. A few hours later it will start up randomly again. Thanks for any help anyone can provide. :)
Cobra97 0 Newbie Poster
Dani AI
Generated
reported that Panda flagged Mitglieder.BO but could not remove it, and that NTVDM.EXE repeatedly spikes CPU. pointed to search results and suggested a tool-based cleanup and general file hygiene. Below are complementary, practical diagnostics and containment steps that avoid repeating the exact tool list already posted and focus on finding how the trojan persists.
Immediate containment and data collection (do these before making big changes):
- Disconnect the machine from the network to prevent further activity or data exfiltration.
- Make a backup of personal documents (do not copy executables).
- Capture a current process and autorun snapshot so helpers can advise:
tasklist /v
wmic process where "caption='ntvdm.exe'" get ProcessId,ParentProcessId,CommandLine,Caption
reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
reg query "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
netstat -ano
schtasks /query /v Read the CommandLine and parent process fields to see which file launches ntvdm.exe. Note any startup entries or scheduled tasks that reference unfamiliar executables. netstat -ano lets you map network connections to PID numbers from tasklist. Paste those outputs (anonymize personal paths) when asking for follow‑up.
About NTVDM: it is the 16‑bit DOS subsystem present only on 32‑bit Windows. A legitimate system will spawn it only to run old DOS/16‑bit programs; persistent, unexplained NTVDM activity often means a program (or malware) is repeatedly launching a DOS stub. On modern 64‑bit systems NTVDM does not exist — its presence there would be highly suspicious.
If diagnostics point to a persistent startup entry or scheduled task you cannot safely remove, the cleanest outcomes are either scanning from an offline/rescue environment (before Windows loads) or a full OS reinstall. Editing the registry or deleting system files can break Windows, so proceed with backups and caution.
Recommended Answers
Jump to Post— pcschrottie 1http://www.google.com/search?hl=en&q=Mitglieder.BO&btnG=Google+Search
Did you try any of these? Their description of how to remove the trojan should be sufficent.
About NTVDM.EXE: it's part of windows and DOS-related, as far as I know.
…
All 2 Replies
pcschrottie 1 Posting Whiz in Training
http://www.google.com/search?hl=en&q=Mitglieder.BO&btnG=Google+Search
Did you try any of these? Their description of how to remove the trojan should be sufficent.
About NTVDM.EXE: it's part of windows and DOS-related, as far as I know.
Michael
caperjack 875 I hate 20 Questions Team Colleague
Hello. I run Panda Software for my antivirus software. When completing a recent scan Panda found the Trojan Mitglieder.BO virus. It said notified but not deleted or quarantined. Does anyone know how to get rid of this virus? It is slowing my system down so much it's ridiculous. I also have a problem with NTVDM.EXE. It keeps opening by itself and using 100% of the processor freezing the system. Any ideas on getting rid of this. The only way I can stop it is by going into task manager and closing the process. A few hours later it will start up randomly again. Thanks for any help anyone can provide. :)
Goand Get Trojan-Hunter Fully working trial! and run a full scan
,,,,,,,,,,,,,,,,,,,,,
To remove trojans there is a tool which needs to be downloaded and run.
1. Please download and save it to your desktop
2. Double-click on the stinger.exe file and open the tool
3. Choose your entire hard drive to scan.
4. Choose Scan Now
5. Stinger will fix anything that it finds
6. Click the File menu and select Save report to file
7. Post the log file results here in this thread.
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Reboot to SAFE mode to delete files
How to start computer in safe mode
Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your , be sure to also select delete all offline content.
Do a virus scan Please do an online scan, 2 would be better,
Micro World
Trend Micro http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure that you choose "fix" or "clean".
.
,,,,,,,,,,,,,,,,,,,,,,,,,,
Download then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.
CWShredder available from these places :-
http://www.aluriasoftware.com/tools/cwshredder.zip
Or this as a full download without any unzipping required
We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from :-
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT
First use Spybot S&D. (Version 1.3)
Spybot
Unzip, and update. Install the updates and run. Delete all that it marks in red.
Reboot
Then it’s time for Ad-Aware
Install and update by using the globe icon. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions to be scanned. When done select all and click next. Remove all checked items and then reboot your computer.
Please go to this page and read the instructions for how to configure Spybot S&D & Ad-Aware
How To Setup Spybot SD and Ad-Aware
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
If needed !!!!!!
Reboot and post a new HiJackThis log. You need an updated version of Hijackthis which you can get from HERE
Then post a HJT log as a reply to this topic.
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.