My brother's Windows user account started misbehaving last night. He could no longer open Internet Explorer, iTunes, Windows Explorer, MSN Messenger, and probably many others he hasn't tried (Firefox is fine). The actual processes do run, but they never get anywhere. For instance, Messenger's system tray icon is there, but I can't right click on it,and the main window never appears,nor does it connect on its own. In the task manager window, iexplore will appear every time i click the shortcut, but the windows never emerge.

I tried running AdAware to scan for problems, and the computer slowed down to the point that it couldn't finish.

I rebooted the computer and logged in on my own account, where everything was working normally. The problem is on his account and his alone. I ran AdAware, and though it found some objects, it didn't fix the problem on his account. I did a complete virus scan of the system and ran Spybot. Trojans and adware showed up on all of the programs, but getting rid of them still has not fixed the problem.

I downloaded hijackthis, if that's what I'll need. I'd really appreciate any help or insight youcould give. Thanks!

Dani AI

Generated

The problem being limited to a single Windows user account (processes appear in Task Manager but their windows never open) points to a per‑user problem rather than a corrupt system binary. was right to push up‑to‑date anti‑malware scans, and confirms a cleaner resolved the immediate symptom. For anyone landing on this thread later, here are targeted diagnostics and a safe repair path that avoid a full OS reinstall.

Targeted diagnostics (least invasive first):

  • Boot to Safe Mode and test the affected account to see whether Explorer/IE behave differently.
  • Create a throwaway local account to confirm the issue is account‑scoped: if the new account works, the profile or HKCU settings are suspect.
  • Check Event Viewer (Application/System) for errors at the time of failed launches.
  • From an admin session load the affected NTUSER.DAT into Regedit (HKEY_USERS → Load Hive) and inspect per‑user keys such as Software\Microsoft\Windows\CurrentVersion\Run, Policies\Explorer, and Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell for stray entries.
  • Use an autoruns/shell‑extension viewer (Process Explorer / Autoruns / ShellExView) to spot and disable non‑Microsoft per‑user startup items and shell extensions, then retest.
  • Verify NTFS permissions on the profile folder and %TEMP% so the account can create temporary files.
  • Run sfc /scannow and chkdsk /f if system files or disk errors are suspected.

Safe profile rebuild (if diagnostics fail): export mail (PST/mbox), bookmarks, and personal data. From an admin account rename or remove the broken profile folder (XP-era: C:\Documents and Settings\username; modern Windows: C:\Users\username) or use System Properties → Advanced → User Profiles → Delete. Log in to create a fresh profile and copy back only user documents and exported settings — do not copy NTUSER.DAT, unknown executables, or uninspected AppData files (those can reintroduce problems). Rescan the cleaned system afterward.

If malware appears persistent or registry edits are unfamiliar, an offline rescue scan from a known‑clean rescue USB or professional assistance is appropriate. Regular backups and keeping AV/anti‑malware definitions current reduce recovery time.

Recommended Answers

All 3 Replies

In addition to Ad Aware and SpyBot, download, install, and run:

ewido Security Suite -
Microsoft Anti-Spyware beta - &displaylang=en

Open each program, use its online update feature to get the most current definitions installed, at run it. After each utility completes its fixes, reboot before continuing on to the next utility; have the utilities fix all of the problematic/malicious items they find.

The ewido utility will generate a report log; save that file and copy/paste it into your next post.

If you have trouble running the utilities while boot into Winodws normally, run the utilities while booted into Safe Mode instead (you get to the safe mode boot option by hitting the F8 key as your computer is starting up).

Microsoft Anti-Spyware didn't do it for me, but Ewido did. Thanks a lot.

You're welcome; glad that worked for you. :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.