Windows XP Community - XPHeads



ntvdm excess CPU usage

microsoft.public.windowsxp.perform_maintain


Reply
  #1 (permalink)  
Old 01-19-2008, 12:05 PM
baffled
 
Posts: n/a
ntvdm excess CPU usage
Hi, after windows XP has been running for an hour or so, ntvdm.exe starts up
and consumes 99% of CPU load. I kill it but it starts up again later. I have
run virus scanners and spybot but found nothing untoward. Only reloaded XP a
month ago so not much gear on the machine yet. I've even tried deleting
ntvdm.exe from \system32\ but it comes back (must be from a WinXP setup file
somewhere on the PC).

Can anyone help me trace what is starting ntvdm, with Process Explorer or
other tools.

Thnks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 01-19-2008, 04:22 PM
peter
 
Posts: n/a
Re: ntvdm excess CPU usage
Ntvdm.exe


Ntvdm.exe is a system process.
When you start a 16-bit program on a computer running Windows NT, the
Ntvdm.exe and Wowexec.exe processes start. After you quit the 16-bit
program, the Ntvdm.exe and Wowexec.exe processes remain in memory. This
behavior is a design feature of Windows NT. The Ntvdm.exe and Wowexec.exe
processes remain in memory in case you start another 16-bit program. Leaving
the Windows-On-Windows (WOW) environment (which consists of the Ntvdm.exe
and Wowexec.exe processes) in memory improves performance. The WOW
environment is not loaded when you start Windows NT. It is loaded when you
first start a 16-bit program.
File ntvdm.exe is related to Findwhatever.
Findwhatever is a browser hijacker that periodically changes Internet
Explorer default home page to various advertising web sites. Findwhatever
doesn't have any harmful payload. It can silently get into the system while
visiting certain web pages. The parasite runs on every Windows startup.

http://www.2-spyware.com/remove-findwhatever.html

peter


--
DISCLAIMER: If you find a posting or message from me
offensive, inappropriate, or disruptive, please ignore it.
If you don't know how to ignore a posting, complain to
me and I will be only too happy to demonstrate... ;-)


"baffled" <baffled@discussions.microsoft.com> wrote in message
news:E8B9191A-B592-41E7-B25F-8EC513A6AF18@microsoft.com...
> Hi, after windows XP has been running for an hour or so, ntvdm.exe starts
> up
> and consumes 99% of CPU load. I kill it but it starts up again later. I
> have
> run virus scanners and spybot but found nothing untoward. Only reloaded XP
> a
> month ago so not much gear on the machine yet. I've even tried deleting
> ntvdm.exe from \system32\ but it comes back (must be from a WinXP setup
> file
> somewhere on the PC).
>
> Can anyone help me trace what is starting ntvdm, with Process Explorer or
> other tools.
>
> Thnks.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-31-2008, 03:42 AM
baffled
 
Posts: n/a
Re: ntvdm excess CPU usage
Thanks for that. I tried this plus many other spy and virus removal
techniques. None of them stopped th eproblem, and none of the tools ever
detected anything malicious on my machine. The only suspicious thing I found
was a lot of extra entires in the hosts file, which is a symptom of some type
of malware getting through.

Eventually I gave up and just re-installed XP, so far so good, will keep my
fingers crossed.

"peter" wrote:

> Ntvdm.exe
>
>
> Ntvdm.exe is a system process.
> When you start a 16-bit program on a computer running Windows NT, the
> Ntvdm.exe and Wowexec.exe processes start. After you quit the 16-bit
> program, the Ntvdm.exe and Wowexec.exe processes remain in memory. This
> behavior is a design feature of Windows NT. The Ntvdm.exe and Wowexec.exe
> processes remain in memory in case you start another 16-bit program. Leaving
> the Windows-On-Windows (WOW) environment (which consists of the Ntvdm.exe
> and Wowexec.exe processes) in memory improves performance. The WOW
> environment is not loaded when you start Windows NT. It is loaded when you
> first start a 16-bit program.
> File ntvdm.exe is related to Findwhatever.
> Findwhatever is a browser hijacker that periodically changes Internet
> Explorer default home page to various advertising web sites. Findwhatever
> doesn't have any harmful payload. It can silently get into the system while
> visiting certain web pages. The parasite runs on every Windows startup.
>
> http://www.2-spyware.com/remove-findwhatever.html
>
> peter
>
>
> --
> DISCLAIMER: If you find a posting or message from me
> offensive, inappropriate, or disruptive, please ignore it.
> If you don't know how to ignore a posting, complain to
> me and I will be only too happy to demonstrate... ;-)
>
>
> "baffled" <baffled@discussions.microsoft.com> wrote in message
> news:E8B9191A-B592-41E7-B25F-8EC513A6AF18@microsoft.com...
> > Hi, after windows XP has been running for an hour or so, ntvdm.exe starts
> > up
> > and consumes 99% of CPU load. I kill it but it starts up again later. I
> > have
> > run virus scanners and spybot but found nothing untoward. Only reloaded XP
> > a
> > month ago so not much gear on the machine yet. I've even tried deleting
> > ntvdm.exe from \system32\ but it comes back (must be from a WinXP setup
> > file
> > somewhere on the PC).
> >
> > Can anyone help me trace what is starting ntvdm, with Process Explorer or
> > other tools.
> >
> > Thnks.

>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 08:47 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74