WMI closed by DEP

Hi,

After applying the last MS patches to a Domain Controller, Data Execution Prevention is closing WMI and don't know the reason.

If I go to DEP manager I can see that DEP is turned on and WMI as an exception but it's unchecked. I guess that somebody added WMI as an exception a time ago and one of those patches recently installed has uncheked the box.

Why is DEP closing WMI?, I wouldn't like to have to add WMI as an exception and I'd like to know what issues or security risks could have if I add WMI to exceptions lists for DEP.

Thank you.
JorgeSimarroVillarAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

JorgeSimarroVillarAuthor Commented:
Any idea?.

Thank you.
0
James MurrellProduct SpecialistCommented:
this may help - helped us a while back
http://www.pcreview.co.uk/forums/thread-176394.php 
0
Jason WatkinsIT Project LeaderCommented:
0
Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

JorgeSimarroVillarAuthor Commented:
Hi Firebar,

I didn't use the WMI Diagnosis Utility, but I followed the steps detailed in the article (http://myitforum.com/cs2/blogs/jgilbert/archive/2008/01/11/how-to-check-the-wmi-repository-before-rebuilding-it.aspx) and didn't get any error in the setup.log after running the command rundll32 wbemupgd, CheckWMISetup.

I think WMI repository is Ok.

Thank you.
0
Jason WatkinsIT Project LeaderCommented:
Hello,

You could disable DEP across the board; http://technet.microsoft.com/en-us/library/cc738483%28WS.10%29.aspx

"AlwaysOff"
0
JorgeSimarroVillarAuthor Commented:
Of course, and I can to add a exception for WMI, but I don't want to disable a security mechanism, just want to know why it's failing just in one of our several servers.
0
ren20atomCommented:
Hi,
As per your above comments it appear that DEP is enabled in your Environment and is being used with Exception.
If that is the rule, possibility appears that somebody who is got administrator rights on the Server has unchecked the WMI exception.
If the above rule is true, you could check other servers in your Environment and if they have WMI checked as an exception, you could check event logs to find out if any exceptions have been modified in DEP on this server.
Alternately you could try a system restore incase you have a System Checkpoint for a date before the patches were applied and check the status of the WMI exception to ensure the patches have not caused the uncheck and then reapply patches manually, but since this is a Server and i am not sure such an amount of Downtime would be available in your Environment.
0
JorgeSimarroVillarAuthor Commented:
Hi,

I think I got it. I tried to stop WMI service and with services.msc and the console showed a pop-up saying that before stopping WMI service I had to stop Office NT Listener (one of the TrendMicro anitivurs product services). It seems that that service has a dependence on WMI service.

I have stopped both services and later have started them again and everything is OK at the moment. I don't know why Trendmicro was messing up everything. I'm try to find out what's the problem.

I'd like to know who added the WMI to the DEP exceptions. Just needed to go to the bottom of the problem.

Thank you.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.