Strange virus attack, what to do?

Discussion in 'ESET Smart Security' started by Question2, Feb 18, 2011.

Thread Status:
Not open for further replies.
  1. Question2

    Question2 Registered Member

    Joined:
    Sep 23, 2010
    Posts:
    33
    Out of nowhere ESET smart security starts reporting that it has blocked connection to a strange address.

    The problem is then my PC is stuck on 100% CPU usage and i can barely do anything.

    After a while i managed to alt-tab to task manager and i see that there are multiple copies of some program called ntvdm.exe and its eating up all my CPU power, and ESET keeps reporting that it is blocking connection to the same address.

    The problem ended after i managed to use task manager to close all the ntvdm.exe processes.

    However when i run a smart scan on default settings, ESET smart security cannot find any threats at all.(With latest updates)

    ntvdm.exe seems to be a file located in C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d

    What should i do now?
     
  2. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
  3. tony_m

    tony_m Eset Staff Account

    Joined:
    Nov 22, 2010
    Posts:
    239
    After submitting the sample to Eset labs, please upload the file to www.virustotal.com

    This service will provide an answer as to which antivirus companies are detecting the file. Please include here what you get.

    Also, a SysInspector log from your system would be helpful.

    How do I create a SysInspector log?

    The best would be to open a ticket with the support department in your country, including all the info and a link to this thread.

    Thanks.
     
  4. Question2

    Question2 Registered Member

    Joined:
    Sep 23, 2010
    Posts:
    33
    Tried to zip it up to submit it to ESET labs, but i just got "access denied".

    Virustotal says the file is clean.
     
  5. Question2

    Question2 Registered Member

    Joined:
    Sep 23, 2010
    Posts:
    33
    And it looks like its set to create these ntvdm.exe processes at 8pm my time everyday...
     
  6. Question2

    Question2 Registered Member

    Joined:
    Sep 23, 2010
    Posts:
    33
    Any ideas on how to get rid of it? Since i cant submit the file to ESET, and according to some pages on the net its probably a virus creating fake ntvdm.exe processes in task manager.
     
  7. reevesloh

    reevesloh Registered Member

    Joined:
    Jul 6, 2009
    Posts:
    160
    Why dun u recover ur window into the day before ur pc infected n see it work or not
     
  8. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
  9. Question2

    Question2 Registered Member

    Joined:
    Sep 23, 2010
    Posts:
    33
    Okay, so when will ESET be able to detect this virus then?
     
  10. yongsua

    yongsua Registered Member

    Joined:
    Feb 9, 2011
    Posts:
    474
    Location:
    Malaysia
    Try to scan with Malwarebytes Anti-Malware or other on demand scanner like Dr web cure It and see whether both of them help or not?
     
Thread Status:
Not open for further replies.