Unsolved

This post is more than 5 years old

56 Posts

22322

March 17th, 2005 13:00

Used HJT, but couldn't solve "Generic Host Process" issues

I don't know if this is an SP2 issue or not, but Midnight Star of HJT fame on of the other forums suggested I post here with this. After running a number of scans & attempting to use the HJT program, we were unable to keep the error message from showing up at boot, as follows:
Data Execution Prevention--
"Generic Host Process for Win32 Services"
was shut down.

Is this something that is going to continue to happen--I mean, is it due to something wrapped up in SP2 that these scans, etc. are going to miss, and that SP2 will continue to flag as a problem. The bottom line is: does it sound like I need to DO something? I plan to upgrade my HDD in a month or two (that Hitachi 60GB @ 7200rpm is looking awfully good), so this may all be a moot point then.

Should I continue being concerned? Thanks for any help anyone can offer.

2 Intern

 • 

2.5K Posts

March 17th, 2005 17:00

I just gotta see the HiJackThis log.  What are your settings for Data Extraction Preventation?

2 Posts

March 17th, 2005 17:00

I had this problem when I bought my HP All-In-One (7300 series).  It was a conflict between their (HP) software and WinXP SP2.

56 Posts

March 17th, 2005 23:00

Strangely enough, we DID recently buy a new HP printer--I wouldn't have thought there was any connection until you mentioned it, but I'm thinking now that THAT would explain why I'm still getting this error message even after reformatting my hard drive & re-installing XP. Here's the logfile:

Logfile of HijackThis v1.99.1
Scan saved at 8:29:07 PM, on 3/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~2\THUNDE~1.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108964307529
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

As far as the data execution prevention settings, how do I determine what they are? *Newbie alert*

2 Intern

 • 

2.5K Posts

March 18th, 2005 00:00

I am sorry, it took me awhile to find them myself, should have included the instructions.  This is for XP Pro, that is what I have - Start -> Control Panel -> System -> Advanced (tab)  -> Settings -> Data Extraction Prevention (tab) .  On my system the top radio button "Turn on DEP for essential Windows+...+" is set.

56 Posts

March 18th, 2005 00:00

I'm running XP Home, but found the spot you were referring to...it was set to "Turn on DEP for essential Windows+...+" as suggested (I'm assuming that "+...+" means "etc." here, so correct me if I'm wrong).

2 Intern

 • 

2.5K Posts

March 18th, 2005 01:00

No you are absolutely correct.  I have a very old/very slow  PC but it has XP I will try looking into this.  No promises.  But, like the cat I am curious.

2 Intern

 • 

2.5K Posts

March 18th, 2005 01:00

56 Posts

March 18th, 2005 01:00

I am, too! Like I said in the original post, I haven't experienced the slow-down or over-working idle process es that I had going on before I reformatted the HDD...the only indication that something is amiss (that I have seen/noticed) is this error message--it shows up once, sometimes twice & then it's done. (SpyBot used to follow it with a request to change a key in the registry [%systemroot%\system32\dumprep0-u] until I indicated it should remember my decision to deny this change from then on.)

Whatever you can offer, I appreciate it! Thanks....

2 Intern

 • 

2.5K Posts

March 18th, 2005 01:00

Here is a thread that you might find interesting http://forums.itweek.co.uk/thread.jsp?forum=10&thread=49793 Ther is also a way of fully disabling DEP. but follow this for a while.  I will continue ot look elsehere.  Did you check with HP, if not that is another source of information.  And a comment, "Not every problem is realated to spyware."

56 Posts

March 18th, 2005 02:00

And I appreciate your earlier comment that not EVERYTHING is due to spyware--I'll bear it in mind! Thanks again!

"Free at last, free at last
I thank God I'm free at last!"

56 Posts

March 18th, 2005 02:00

Surprise!
I played with the settings for the DEP function in the System area of Control Panel (per suggestions from both sites you referenced in the last few posts), and when I set it to apply the DEP for only ESSENTIAL processes, my COMPUTER DIDN'T SHOW THE ERROR MESSAGE AT BOOT-UP!!! HOORAY!!!!!

So tired now....

2 Posts

March 18th, 2005 03:00

There is also a patch that you can get off the HP website that will fix any conflicts with XP SP2.
No Events found!

Top