Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Error:


  • Please log in to reply
24 replies to this topic

#1 AkaAlias

AkaAlias

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Location:Roermond, The Netherlands
  • Local time:02:42 AM

Posted 14 March 2005 - 04:16 AM

I sometimes get the following error after startup.

Posted Image


Have Windows XP with sp2

Scans with Norton, HJT and SB s&d gave no results.

Does anyone have any idea what causes this..??

greets,

Stefan
Posted Image

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:42 AM

Posted 16 March 2005 - 05:20 PM

Can you translate that to english for me?

#3 AkaAlias

AkaAlias
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Location:Roermond, The Netherlands
  • Local time:02:42 AM

Posted 16 March 2005 - 05:52 PM

It says something like..:

----
In Generic Host Process for Win32 Services occurred an error en must bed closed. Our appologies for this inconvenience.
----
All the other text is saying that u can send an error report or don't. Etc...

(send report) (don't send)

----
Posted Image

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:42 AM

Posted 16 March 2005 - 11:58 PM

Please run two online virus scans:

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
http://housecall.antivirus.com/

Then let us know if its working better and what the scans found.

#5 AkaAlias

AkaAlias
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Location:Roermond, The Netherlands
  • Local time:02:42 AM

Posted 17 March 2005 - 10:03 AM

Both scans found absolutely nothing. No viruses of any kind.
Posted Image

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:42 AM

Posted 17 March 2005 - 10:40 AM

Unfortunately this error could be from anything. You can try running msconfig (start, run, type msconfig and press enter, then click on the startup tab) and unchecking items, rebooting, and seeing if the error goes away to determine if its a problem with a particular program thats starting up

#7 Tiberia

Tiberia

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:02:42 AM

Posted 17 March 2005 - 10:41 AM

Go to run and type...
msconfig
In the windows go to the startup tab see here which programs start when your windows start.
Uncheck all unnecessary programs that you don't like to loud....
Restart and see the error comes or not…
If it still comes uncheck all the program in the startup tab of msconfig…
And restart…
And see the error comes or not…
But remember this way all program will not be lauded at startup like Antivirus softwares, firewalls, messengers etc…
I’ll recommend to uncheck all of them and restart your Antivirus firewall and other stuff manually…
If it works please tell us…
"Tiberia"

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:42 AM

Posted 17 March 2005 - 12:17 PM

Cheers Tiberia :thumbsup: We are both on the same track!

#9 AkaAlias

AkaAlias
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Location:Roermond, The Netherlands
  • Local time:02:42 AM

Posted 18 March 2005 - 10:58 AM

The weird thing about the error is, that it doesn't happen all the time. Sometimes it does after startup but most of the time it doesn't.. So i don't see why it could be any of the programs in msconfig... what could cause this error to appear only once in a while.. and not every time when i boot the comp..??

Thanks for your time!

Edited by AkaAlias, 18 March 2005 - 10:58 AM.

Posted Image

#10 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:03:42 AM

Posted 18 March 2005 - 11:57 AM

What are the changes?

Where there any programs that you loaded, or uninstalled prior to the error appearing?
Is this happening on the first boot of the day, or does it occur after a warm/cold boot?

Do a Ctrl - Alt - Delete and check to see what services and processes are running while you have the error message up. Anything noticeably odd? (Grinler - Tiberia... Do you know of a program that captures running processes and exports to a text file? HJT?)

Thinking out load... I wonder if whatever causes the error shows up as a selection for msconfig if the error only occurs at certain times.

Rigel

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#11 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:42 AM

Posted 18 March 2005 - 03:51 PM

Hijackthis log will show running processes

#12 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:03:42 AM

Posted 18 March 2005 - 08:53 PM

AkaAlias... can you post a HJT log that was run while the error is being displayed on your computer? If it doesn't happen at every boot, maybe something will show at the time of error.

The HJT guys will have to analyze it... even though I am curious to see of I can find something :thumbsup:

Rigel

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#13 AkaAlias

AkaAlias
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Location:Roermond, The Netherlands
  • Local time:02:42 AM

Posted 19 March 2005 - 05:02 AM

The error hasn't occurd in a while. When it does i will make a hjt-log, untill that time, here is a hjt-log without the error occuring, maybe u can find something..

Thank you for your help!

---
Logfile of HijackThis v1.99.0
Scan saved at 11:00:12, on 19-3-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
D:\Program Files\Norton AntiVirus\SAVScan.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Tablet.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Messenger Plus! 3\MsgPlus.exe
D:\WINDOWS\system32\CTHELPER.EXE
D:\Program Files\Java\jre1.5.0\bin\jusched.exe
D:\Program Files\D-Tools\daemon.exe
C:\Mijn appz\TaskSwitchXP\TaskSwitchXP.exe
D:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
D:\WINDOWS\system32\Wtablet\TabUserW.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Soulseek\slsk.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Winamp\winamp.exe
D:\Program Files\Messenger\msmsgs.exe
C:\Mijn appz\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] D:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [MessengerPlus3] "D:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "D:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MessengerPlus3] "D:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Mijn appz\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = D:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = D:\WINDOWS\system32\Wtablet\TabUserW.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1105724443504
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BB7BE230-BE80-4C51-BF8D-947A0B48996D}: NameServer = 195.121.1.254,195.240.240.254
O23 - Service: Adobe LM Service - Unknown - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sflpnotkaapp - Unknown - (no file)
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TabletService - Wacom Technology, Corp. - D:\WINDOWS\system32\Tablet.exe
Posted Image

#14 rigel

rigel

    FD-BC


  • Members
  • 12,944 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:03:42 AM

Posted 19 March 2005 - 10:53 AM

Cool. I am interested to see if there is a change.

Any thoughts on HJT log Grinler?

*I searched and was curious as to what \soulseek\slsk.exe was. I couldn't find that anywhere.

023 - Service:Sflpnotkaapp - unknown - no file not sure what this is either. Figure it relates to R0 entry = Koppelingen*

The HJT team will know more

****Note: AkaAlias - I am not a HJT team member. Please don't do anything with the HJT log until one of their team looks at it.

I am just using it as a comparison to see if anything changes during the error.

Edited by rigelslight, 19 March 2005 - 01:31 PM.

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith


#15 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,640 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:03:42 AM

Posted 19 March 2005 - 02:22 PM

I agree this does not look kosher:

O23 - Service: Sflpnotkaapp - Unknown - (no file)

I will disable the service.

Other than that looks good




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users