Done multiple virus scans with Norton, scanned with ad-aware SE, spybot s&d, re-upgraded the xp pro install. For some reason, Yahoo Instant Messenger, MSN Messenger, Internet Explorer, and Hijackthis, all crash immediately when opened, and give me that stupid blahblahblah has caused a problem and needs to close. I haven't recently installed or changed anything. I have done 2 system restores, and all attempts to un-install, re-install these programs has failed with the install wizard closing due to some insane problem. What the hell? Anyone have any suggestions?
20gauge 0 Newbie Poster
Dani AI
Generated
Good first troubleshooting by and the diagnostic work by — the fact that the affected apps run in Safe Mode (while others do not) is a very useful signal: this strongly points to a third‑party startup item, shell extension, service, or browser helper rather than core Windows files.
Recommended, ordered troubleshooting (practical workflow)
- Perform a clean boot using msconfig: enable Selective Startup, hide Microsoft services, disable the remaining services and all non‑Microsoft startup items, then reboot to test. If the crash goes away, re‑enable items in halves (binary search) until the offending entry is found.
- Use Autoruns (Sysinternals) to inspect and selectively disable suspicious entries under Logon, Explorer and Internet Explorer/BHOs. Focus on unknown items and unsigned DLLs.
- Check Event Viewer (Application) for the crash entry and note the faulting module/DLL. That filename is the best clue to the culprit; once identified, remove or quarantine that component from Safe Mode after backing it up.
- Create a fresh local user account and test the same apps there — a profile‑specific problem will show up immediately.
- After isolating/removing the offender, run up‑to‑date on‑demand scanners and then reinstall the affected IM/IE components.
Cautions and final notes
- Always back up registry and important files before editing or deleting system entries. Create a restore point (or full backup) so changes can be undone.
- If the problem resists isolation (rootkit, persistent service, or corrupted system binaries), consider an in‑place repair or clean OS reinstall as a last resort — after backing up data.
These steps build on the Safe Mode observation and the host/scan work already done and should let the original poster narrow the cause without repeating full reinstall attempts.
Recommended Answers
Jump to Post— pcschrottie 1Try to open some of these programs in safe mode. If they work there, then it could be malware causing the problem.
Michael
Jump to Post— pcschrottie 1a couple of trojans
Some people would say: reinstall Windows.
Hijackthis freezes when it is scanning hosts file redirection
Well then, look into the hosts file. There shouldn't be anything else than localhost 127.0.0.1.
Michael
All 5 Replies
pcschrottie 1 Posting Whiz in Training
Try to open some of these programs in safe mode. If they work there, then it could be malware causing the problem.
Michael
20gauge 0 Newbie Poster
Well, they all work in Safe Mode, except for hijackthis. It locks up mid-scan either way. I have the newest defs. for Norton, and have found a couple of trojans(trojan.byteverify) and removed them, but I am still having the problem. All the trojans were found in a cache file in the application data folder for java RE. I have since deleted that entire folder (I removed Java RE in the process of all this trying to find out what was going on). But still no good, Hijackthis freezes when it is scanning hosts file redirection, I don't know if that helps. Norton scan now returns nothing.
pcschrottie 1 Posting Whiz in Training
a couple of trojans
Some people would say: reinstall Windows.
Hijackthis freezes when it is scanning hosts file redirection
Well then, look into the hosts file. There shouldn't be anything else than localhost 127.0.0.1.
Michael
20gauge 0 Newbie Poster
There was a lot of different crap in there, mostly going to , and a few other IP's, so I downloaded a hosts file that is supposed to be windows default, and I replacing it now, any other suggestions?
20gauge 0 Newbie Poster
Hijack this works now, here is the log:
Logfile of HijackThis v1.98.2
Scan saved at 1:18:12 PM, on 3/17/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\r_server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Documents and Settings\User\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\JORDAN~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\JORDAN~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {952EC4CB-AB55-4E25-BBFF-01F5331933BF} - C:\WINDOWS\System32\bofe.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [loader32] C:\WINDOWS\loader32.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [aox5ROJ7e] imgllreg.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (file missing) (HKCU)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O15 - Trusted Zone: *.
O15 - Trusted Zone: *.
O15 - Trusted Zone: *.windupdates.com
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.