Hello Frnds,

I have a problem which is not going to solve..
actually the prob is wen i load turbo c++ dos version on any client system than the cpu usage rises to 100%, and the system starts no responding situation for other programs.

following is the log generated by hijackthis, in which a doubtful process is identified but i can't fix it. neither an antivirus like etrust can't remove it. and also it can't be stopped the file name is ntvdm.exe. any one who can help me through this prob


Logfile of HijackThis v1.99.1
Scan saved at 5:17:18 PM, on 9/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Borland\InterBase\bin\ibguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Borland\InterBase\bin\ibserver.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\autodown.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = aserver:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = kust.edu.pk
O17 - HKLM\Software\..\Telephony: DomainName = kust.edu.pk
O17 - HKLM\System\CCS\Services\Tcpip\..\{28E2BD82-0558-4E34-AFE9-656FFBD3B35E}: NameServer =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = kust.edu.pk
O17 - HKLM\System\CS1\Services\Tcpip\..\{28E2BD82-0558-4E34-AFE9-656FFBD3B35E}: NameServer =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = kust.edu.pk
O17 - HKLM\System\CS2\Services\Tcpip\..\{28E2BD82-0558-4E34-AFE9-656FFBD3B35E}: NameServer =
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Borland Software Corporation - C:\Program Files\Borland\InterBase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Borland Software Corporation - C:\Program Files\Borland\InterBase\bin\ibserver.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: Visibroker Activation Daemon (oad) - Unknown owner - C:\Inprise\vbroker\bin\oad.exe
O23 - Service: VisiBroker Smart Agent (osagent) - Unknown owner - C:\Inprise\vbroker\bin\osagent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

Recommended Answers

All 3 Replies

The problem is that most old DOS programs, your version of Turbo C++ included, constantly poll for keypresses. Since the DOS environment is being emulated, this means that the program is maxing out the emulation process's processor usage. If you check your process list in the Task Manager as this is happening, you will most likely see NTVDM.exe taking up most of the processor since this is the emulation process.

The fix for this problem is to upgrade to Turbo C++ 5.5 or higher. Another way to fix this is to switch to a different IDE/compiler. Is there a specific reason why you need to use this version?

ntvdm is a legitimate process used by windows to emulate a dos environment. It's not spyware.

i also have the same problem,
i have a network in da company and using citrix,
but i found always the processor usage goes to high in the server which cause the slowness,
and i found the ntvdm.exe is the process which causing that,
what should i do to solve it?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.