Data Execution Prevention

I

Ian

I have a notebook running XP. When it starts it always shows an error message
"Data Execution Prevention" with a message " Boot Acceptance Application for
Registry". If I open Task Manager - File- New Task (Run) and type C: the
desktop appears. Can anyone help to fix this problemplease?
 
N

nass

Ian said:
I have a notebook running XP. When it starts it always shows an error message
"Data Execution Prevention" with a message " Boot Acceptance Application for
Registry". If I open Task Manager - File- New Task (Run) and type C: the
desktop appears. Can anyone help to fix this problemplease?

Description of the Date Execution Prevention feature in SP2:
http://support.microsoft.com/default.aspx?kbid=875352&product=windowsxpsp2

Use the ShellExView to monitor in real time what cuaing the DEP issue:
http://www.nirsoft.net/utils/shexview.html

What is DEP? and how to disable it:
http://msdn.microsoft.com/en-us/library/ms791539(printer).aspx
Turn the DEP OFF:
http://technet.microsoft.com/en-us/library/cc700810.aspx
http://www.techsupportforum.com/mic...02-dep-prevents-opening-windows-explorer.html

Your machine my be infected so Go through these cleaning steps:

1... Click start >> Control Panel >> Double Click Network and Internet
Connections >> Double click Internet Options, on the IE Properties window
you will see these Options:
General | Security | Privacy | Content | Connections | Programs
| Advanced .

Click on General Tab (1st Tab on the left) and you will see a Button called
[ Clear History ..] click on it to clear your History caches, then click on
[Delete Files..] to delete Internet Files created over the time, click on [
Delete Cookies...] to delete your cookies left by visiting websites.

= Then try to Disable the Add-Ons on your Browser somehow installed on your
browser, On how to disable the Add-ons follow this:
Click on Programs Tab and then click the Manage Add-Ons Button there Disable
the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
later and see which is the culprit or you can send them here in your next
post) and click [OK] to confirm your Changes.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256

Click on Advanced Tab and scroll down under the browsing option and uncheck
this box:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) and click Apply
then OK to close your IE Properties.
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

http://onecare.live.com/site/en-gb/default.htm?s_cid=sah
http://onecare.live.com/standard/en-gb/default.htm
Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html
Comodo BOClean : Anti-Malware Version 4.27
http://www.comodo.com/boclean/boclean.html
Run diskm cleanup then this command:
sfc /scannow

Have a look in the Event Viewer for error messages(X) that can shed some
light and post it back in your next post by performing the following and also
the System File Checker (SFC) sfc /scannow:

Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

Let us know your findings.
HTH,
nass
 
I

Ian

Here is the data from the event veiwer. I it will help. I completed all
the other task. Just need to scan the disk with the apps you suggested.
Thanks for your help.
Ian


Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 17/03/2009
Time: 10:43:54
User: N/A
Computer: HPLAPTOP
Description:
Faulting application userinit.exe, version 5.0.2134.1, faulting module
userinit.exe, version 5.0.2134.1, fault address 0x00009134.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 75 73 65 ure use
0018: 72 69 6e 69 74 2e 65 78 rinit.ex
0020: 65 20 35 2e 30 2e 32 31 e 5.0.21
0028: 33 34 2e 31 20 69 6e 20 34.1 in
0030: 75 73 65 72 69 6e 69 74 userinit
0038: 2e 65 78 65 20 35 2e 30 .exe 5.0
0040: 2e 32 31 33 34 2e 31 20 .2134.1
0048: 61 74 20 6f 66 66 73 65 at offse
0050: 74 20 30 30 30 30 39 31 t 000091
0058: 33 34 34


Event Type: Failure Audit
Event Source: Security
Event Category: Policy Change
Event ID: 615
Date: 17/03/2009
Time: 10:43:51
User: NT AUTHORITY\NETWORK SERVICE
Computer: HPLAPTOP
Description:
IPSec Services: IPSec Services failed to get the complete list of network
interfaces on the machine. This can be a potential security hazard to the
machine since some of the network interfaces may not get the protection as
desired by the applied IPSec filters. Please run IPSec monitor snap-in to
further diagnose the problem.



For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.



nass said:
Ian said:
I have a notebook running XP. When it starts it always shows an error message
"Data Execution Prevention" with a message " Boot Acceptance Application for
Registry". If I open Task Manager - File- New Task (Run) and type C: the
desktop appears. Can anyone help to fix this problemplease?

Description of the Date Execution Prevention feature in SP2:
http://support.microsoft.com/default.aspx?kbid=875352&product=windowsxpsp2

Use the ShellExView to monitor in real time what cuaing the DEP issue:
http://www.nirsoft.net/utils/shexview.html

What is DEP? and how to disable it:
http://msdn.microsoft.com/en-us/library/ms791539(printer).aspx
Turn the DEP OFF:
http://technet.microsoft.com/en-us/library/cc700810.aspx
http://www.techsupportforum.com/mic...02-dep-prevents-opening-windows-explorer.html

Your machine my be infected so Go through these cleaning steps:

1... Click start >> Control Panel >> Double Click Network and Internet
Connections >> Double click Internet Options, on the IE Properties window
you will see these Options:
General | Security | Privacy | Content | Connections | Programs
| Advanced .

Click on General Tab (1st Tab on the left) and you will see a Button called
[ Clear History ..] click on it to clear your History caches, then click on
[Delete Files..] to delete Internet Files created over the time, click on [
Delete Cookies...] to delete your cookies left by visiting websites.

= Then try to Disable the Add-Ons on your Browser somehow installed on your
browser, On how to disable the Add-ons follow this:
Click on Programs Tab and then click the Manage Add-Ons Button there Disable
the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
later and see which is the culprit or you can send them here in your next
post) and click [OK] to confirm your Changes.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256

Click on Advanced Tab and scroll down under the browsing option and uncheck
this box:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) and click Apply
then OK to close your IE Properties.
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

http://onecare.live.com/site/en-gb/default.htm?s_cid=sah
http://onecare.live.com/standard/en-gb/default.htm
Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html
Comodo BOClean : Anti-Malware Version 4.27
http://www.comodo.com/boclean/boclean.html
Run diskm cleanup then this command:
sfc /scannow

Have a look in the Event Viewer for error messages(X) that can shed some
light and post it back in your next post by performing the following and also
the System File Checker (SFC) sfc /scannow:

Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

Let us know your findings.
HTH,
nass
 
N

nass

Ian said:
Here is the data from the event veiwer. I it will help. I completed all
the other task. Just need to scan the disk with the apps you suggested.
Thanks for your help.
Ian


Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 17/03/2009
Time: 10:43:54
User: N/A
Computer: HPLAPTOP
Description:
Faulting application userinit.exe, version 5.0.2134.1, faulting module
userinit.exe, version 5.0.2134.1, fault address 0x00009134.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 75 73 65 ure use
0018: 72 69 6e 69 74 2e 65 78 rinit.ex
0020: 65 20 35 2e 30 2e 32 31 e 5.0.21
0028: 33 34 2e 31 20 69 6e 20 34.1 in
0030: 75 73 65 72 69 6e 69 74 userinit
0038: 2e 65 78 65 20 35 2e 30 .exe 5.0
0040: 2e 32 31 33 34 2e 31 20 .2134.1
0048: 61 74 20 6f 66 66 73 65 at offse
0050: 74 20 30 30 30 30 39 31 t 000091
0058: 33 34 34


Event Type: Failure Audit
Event Source: Security
Event Category: Policy Change
Event ID: 615
Date: 17/03/2009
Time: 10:43:51
User: NT AUTHORITY\NETWORK SERVICE
Computer: HPLAPTOP
Description:
IPSec Services: IPSec Services failed to get the complete list of network
interfaces on the machine. This can be a potential security hazard to the
machine since some of the network interfaces may not get the protection as
desired by the applied IPSec filters. Please run IPSec monitor snap-in to
further diagnose the problem.



For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Hi Ian,

Q= Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 17/03/2009
Time: 10:43:54
User: N/A
Computer: HPLAPTOP
Description:
Faulting application userinit.exe, version 5.0.2134.1, faulting module
userinit.exe, version 5.0.2134.1, fault address 0x00009134.


A = Try to replace the copy of userinit.exe which located in
here:C:\Windows\system32 from your CD or run this command from
the run command:

SFC /SCANNOW

Reboot your machine after the system file checker finishes the scan and see
if the error will reoccur.

=============================================================
Q= Event Type: Failure Audit
Event Source: Security
Event Category: Policy Change
Event ID: 615
Date: 17/03/2009
Time: 10:43:51
User: NT AUTHORITY\NETWORK SERVICE
Computer: HPLAPTOP
Description:
IPSec Services: IPSec Services failed to get the complete list of network
interfaces on the machine. This can be a potential security hazard to the
machine since some of the network interfaces may not get the protection as
desired by the applied IPSec filters. Please run IPSec monitor snap-in to
further diagnose the problem.

A= Can you tell me about your machine and in which environement does it
operate?
Do you shre or a member in a domain/workgroup?


If you need more help Download the Hijackthis and send the report to one of
many
forums for analysis and troubleshooting or you can send it to me on my email
provided at the bottom:
When all else fails, HijackThis v2.0.2
(http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php)

Can you please send me a copy at (e-mail address removed) ,
remove the obvious to email me.

HTH,
nass
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top