What is "TDIHOOK service"? Thank you!
Results 1 to 14 of 14

Thread: What is "TDIHOOK service"? Thank you!

  1. #1
    Registered User
    Join Date
    Apr 2004
    Posts
    9

    What is "TDIHOOK service"? Thank you!

    Hi, I found this error message in my WINXP Event viewer: The TDIHOOK service failed to start due to the following error: The system cannot find the file specified.
    So what's this service? How can I correct it?
    My Winxp cannot shutdown, but instead restart. I think this maybe one of the reason. Is there any other posiibilities?
    Thank you.

  2. #2
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    It does not appear in xp services I would treat this service with suspicion - http://housecall.antivirus.com do an online check that cannot be incapacitated.

  3. #3
    Intel Mod Platypus's Avatar
    Join Date
    Jan 2001
    Location
    Australia
    Posts
    5,783
    I concur, assuming you are running a firewall, you may have a problem which could be part of a hijack, preventing a TDI or NDIS filter-hook from loading could be an attack on a firewall.

    If nothing shows up in malware checking, maybe try re-installing your firewall if you are using a third-party program. Or if this started happening after a specific operation on your system like a program installation or removal, system cleanup etc, maybe try a restore to a point prior to that occurrence.
    Last edited by Platypus; April 11th, 2004 at 05:52 AM.

  4. #4
    Registered User
    Join Date
    Apr 2004
    Posts
    9
    Sorry for the late reply and thank you NooNoo.
    I scaned my computer and no virus found. By the way, I am using norton personal firewall 2003. Any other hints?

    Quote Originally Posted by NooNoo
    It does not appear in xp services I would treat this service with suspicion - http://housecall.antivirus.com do an online check that cannot be incapacitated.

  5. #5
    Registered User
    Join Date
    Apr 2004
    Posts
    9
    Sorry for the late reply and thank you Platypus.
    Seems it's hard for me to determine which is the cause. From what you said, an attack on my firewall is most possible. This error report happens each time I shut down my winxp.


    Quote Originally Posted by Platypus
    I concur, assuming you are running a firewall, you may have a problem which could be part of a hijack, preventing a TDI or NDIS filter-hook from loading could be an attack on a firewall.

    If nothing shows up in malware checking, maybe try re-installing your firewall if you are using a third-party program. Or if this started happening after a specific operation on your system like a program installation or removal, system cleanup etc, maybe try a restore to a point prior to that occurrence.

  6. #6
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Please post a list of your processes.

  7. #7
    Registered User
    Join Date
    Apr 2004
    Posts
    9
    Hi, NooNoo, the processes of my computer are:
    iexplore.exe
    taskmgr.exe
    msgsys.exe
    nvsvc32.exe
    matlab.exe
    rtvscan.exe
    matlabserver.exe
    defwatch.exe
    ccPxySvc.exe
    alg.exe
    spoolsv.exe
    NISUM.EXE
    ccEvtMgr.exe
    explorer.exe
    svchost.exe (system)
    svchost.exe (local service)
    svchost.exe(network service)
    svchost.exe(system)
    svchost.exe(system)
    lsass.exe
    service.exe
    winlogon.exe
    csrss.exe
    smss.exe
    ctfmon.exe
    ccApp.exe
    Ad-watch.exe
    vptray.exe
    rundll32.exe
    system
    system idle process

    Thank you.
    Quote Originally Posted by NooNoo
    Please post a list of your processes.

  8. #8
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Nothing out of the ordinary there. I could well be that Norton Firewall is causing this problem.

    In the event viewer, what other information is there?
    Event ID ?

  9. #9
    Registered User
    Join Date
    Apr 2004
    Posts
    9
    Event ID is: 7000
    Thank you.


    Quote Originally Posted by NooNoo
    Nothing out of the ordinary there. I could well be that Norton Firewall is causing this problem.

    In the event viewer, what other information is there?
    Event ID ?

  10. #10
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    7000 - such a wonderfully informative number....

    TDIHOOK if it is spelt exactly like that, should show up in the registry somewhere, probably more than once.

    Start, run, regedit
    Edit find, TDIHOOK
    if it finds one, right click the key, copy key and paste it into a post here please.

  11. #11
    Registered User
    Join Date
    Apr 2004
    Posts
    9
    I searched, got nothing for this key word:TDIHOOK in my registry. Weired!

    Quote Originally Posted by NooNoo
    7000 - such a wonderfully informative number....

    TDIHOOK if it is spelt exactly like that, should show up in the registry somewhere, probably more than once.

    Start, run, regedit
    Edit find, TDIHOOK
    if it finds one, right click the key, copy key and paste it into a post here please.

  12. #12
    Registered User MobilePCPhysician's Avatar
    Join Date
    Jan 2002
    Location
    Cleveland, Oh
    Posts
    2,381
    Since you're running Norton Firewall, is Windows XP firewall also running?

    FILENAME: Alg.exe.
    PROGRAM NAME: Application Layer Gateway.
    DESCRIPTION: Part of Windows XP that provides support for ICS and Internet Connection Firewall (ICF).
    RECOMMENDED ACTION: If a third-party firewall warns you that ALG.exe wants access, check to make sure you're not double-firewalled. If you are, disable ICF. If you are using neither ICF nor ICS and are warned that ALG.exe is trying to access the Net, deny it. A Trojan horse or worm may be trying to use it as a backdoor.

    this may cause Windows to not shutdown. Hope it helps.

  13. #13
    Registered User
    Join Date
    Apr 2004
    Posts
    9
    Thank you so much.
    After I disabled the winxp firewall, my computer can shut down correctly now and no such error reported any more.
    Thank you all you guys for the help.

    Quote Originally Posted by MobilePCPhysician
    Since you're running Norton Firewall, is Windows XP firewall also running?

    FILENAME: Alg.exe.
    PROGRAM NAME: Application Layer Gateway.
    DESCRIPTION: Part of Windows XP that provides support for ICS and Internet Connection Firewall (ICF).
    RECOMMENDED ACTION: If a third-party firewall warns you that ALG.exe wants access, check to make sure you're not double-firewalled. If you are, disable ICF. If you are using neither ICF nor ICS and are warned that ALG.exe is trying to access the Net, deny it. A Trojan horse or worm may be trying to use it as a backdoor.

    this may cause Windows to not shutdown. Hope it helps.

  14. #14
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    *NooNoo files that one for future reference.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •