Ntvdm.exe
Ntvdm.exe is a system process.
When you start a 16-bit program on a computer running Windows NT, the
Ntvdm.exe and Wowexec.exe processes start. After you quit the 16-bit
program, the Ntvdm.exe and Wowexec.exe processes remain in memory. This
behavior is a design feature of Windows NT. The Ntvdm.exe and Wowexec.exe
processes remain in memory in case you start another 16-bit program. Leaving
the Windows-On-Windows (WOW) environment (which consists of the Ntvdm.exe
and Wowexec.exe processes) in memory improves performance. The WOW
environment is not loaded when you start Windows NT. It is loaded when you
first start a 16-bit program.
File ntvdm.exe is related to Findwhatever.
Findwhatever is a browser hijacker that periodically changes Internet
Explorer default home page to various advertising web sites. Findwhatever
doesn't have any harmful payload. It can silently get into the system while
visiting certain web pages. The parasite runs on every Windows startup.
http://www.2-spyware.com/remove-findwhatever.html
peter

Signature
DISCLAIMER: If you find a posting or message from me
offensive, inappropriate, or disruptive, please ignore it.
If you don't know how to ignore a posting, complain to
me and I will be only too happy to demonstrate... ;-)
> Hi, after windows XP has been running for an hour or so, ntvdm.exe starts
> up
[quoted text clipped - 11 lines]
>
> Thnks.
baffled - 31 Jan 2008 03:42 GMT
Thanks for that. I tried this plus many other spy and virus removal
techniques. None of them stopped th eproblem, and none of the tools ever
detected anything malicious on my machine. The only suspicious thing I found
was a lot of extra entires in the hosts file, which is a symptom of some type
of malware getting through.
Eventually I gave up and just re-installed XP, so far so good, will keep my
fingers crossed.
> Ntvdm.exe
>
[quoted text clipped - 33 lines]
> >
> > Thnks.