Application Failed to initialize because the windows station is shutting down

Posted 2/21/2005 10:24 AM
#10178
User avatar

TacoBelle Member

Date Joined Nov 2016
Total Posts: 3
I have a clean install of Win XP with the service pack installed (have used 98 till now). I have AdAware, Spybot, CWShredder and the Microsoft Spyware scanner installed and up-to-date and have been running them. I have the Microsoft firewall, but haven't even had a chance to install anything else yet, it's so new. I also have AVG virus scanner. None of them indicate a specific problem (in fact the MS Spyware doesn't even find the regular spyware that AdAware and Spybot find). All my Windows Updates are up-to-date. I've been working on installing my software over the past 5 days when suddenly I began to get the following message: <br/> <br/> <br/>"The application failed to initialize because the windows station is shutting down" when I shut down or reboot the computer. <br/> <br/> <br/> <br/>It goes by so fast that it could be different than that, but that's what I've been able to see. <br/> <br/> <br/> <br/>I searched around for solutions to this and have read that it's a trojan...Frustrating when I've never had one before and then suddenly on a brand fresh hard drive. Why? <br/> <br/> <br/> <br/>Anyway I read some info on the Symantec page but couldn't find all of the things they said I'd find, when I looked. So I've run Hijackthis and am including a log. If you can help me, I certainly would appreciate it. <br/> <br/> <br/> <br/>TacoBelle <br/> <br/> <br/> <br/>Logfile of HijackThis v1.97.7 <br/>Scan saved at 4:48:01 AM, on 2/21/2005 <br/>Platform: Windows XP SP2 (WinNT 5.01.2600) <br/>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) <br/> <br/>Running processes: <br/>C:\WINDOWS\System32\smss.exe <br/>C:\WINDOWS\system32\winlogon.exe <br/>C:\WINDOWS\system32\services.exe <br/>C:\WINDOWS\system32\lsass.exe <br/>C:\WINDOWS\system32\svchost.exe <br/>C:\WINDOWS\System32\svchost.exe <br/>C:\WINDOWS\system32\spoolsv.exe <br/>C:\WINDOWS\Explorer.EXE <br/>C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe <br/>C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe <br/>C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE <br/>C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE <br/>C:\WINDOWS\system32\svchost.exe <br/>C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe <br/>C:\WINDOWS\system32\NVATray.exe <br/>C:\Program Files\Microsoft AntiSpyware\gcasServ.exe <br/>C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe <br/>C:\Program Files\HP\hpcoretech\hpcmpmgr.exe <br/>C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe <br/>C:\WINDOWS\system32\hphmon05.exe <br/>C:\WINDOWS\SYSTEM32\USRmlnkA.exe <br/>C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe <br/>C:\WINDOWS\SYSTEM32\USRshutA.exe <br/>C:\WINDOWS\SYSTEM32\USRmlnkA.exe <br/>C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe <br/>C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe <br/>C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe <br/>C:\Program Files\DLMage\DnloadMage.exe <br/>C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe <br/>C:\WINDOWS\system32\HPZipm12.exe <br/>C:\Program Files\Internet Explorer\IEXPLORE.EXE <br/>C:\Program Files\ICQ\ICQ.exe <br/>C:\Bin\Spyware Scanners\HijackThis.exe <br/> <br/>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/ <br/>O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll <br/>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll <br/>O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll <br/>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll <br/>O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe <br/>O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" <br/>O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k <br/>O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe <br/>O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe <br/>O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe <br/>O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" <br/>O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" <br/>O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe <br/>O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA <br/>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP <br/>O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe <br/>O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\ICQ\ICQNet.exe <br/>O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe <br/>O4 - HKCU\..\RunOnce: [ICQ] C:\Program Files\ICQ\ICQ.exe -trayboot <br/>O4 - Startup: Download Mage.lnk = C:\Program Files\DLMage\DnloadMage.exe <br/>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe <br/>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe <br/>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE <br/>O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe <br/>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html <br/>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html <br/>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html <br/>O8 - Extra context menu item: Download Links As... - http://office.microsoft.com/officeupdate/content/opuc.cab <br/>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107889283656 <br/>O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab <br/>O17 - HKLM\System\CCS\Services\Tcpip\..\{60FF2FE1-B305-4D7F-AAAC-1A657AE4B329}: NameServer = 204.255.213.26 204.255.212.245
Posted 2/22/2005 3:34 AM
#10214
User avatar

Smiley_wiz02 Member

Date Joined Nov 2016
Total Posts: 1
my friend is having the same problem. That thing appears saying the exact same thing, and here is what she did to fix the trojan. Shes still in the process of fixing it, so email me if u have any questions (Smiley_wiz02@yahoo.com) <br/> <br/>On My Computer icon, right click, and go to Properties <br/>Go to System Restore tab, and check the turn off system restore <br/>click apply, and ok <br/> <br/>restart ur computer in safe mode (when u restart, constantly press the F8 key) <br/>start in safe mode, and then run a full scan. <br/> <br/>once it finds it, delete the virus, and restart in normal mode. <br/> <br/>Lets see if this help, hopefully it will
Posted 2/23/2005 4:09 AM
#10272
User avatar

TacoBelle Member

Date Joined Nov 2016
Total Posts: 3
I have been doing some more reading on this topic and I am not convinced this is a virus at all. I went to www.microsoft.com and did a search in the Knowledge Base and although the specifics weren't the same, they didn't indicate that it was a virus at all. I am not sure what to do. I thought the log would tell if there truly is a trojan or not. Since I don't know what to delete, the advice doesn't really help me. I will continue to research till I know for sure. Thanks for trying to help.
Posted 2/23/2005 5:08 PM
#10305
User avatar

anthonywest Member

Date Joined Nov 2016
Total Posts: 1
I agree with TacoBelle's hypothesis. <br/> <br/>I also had a clean, well-protected WinXP Pro SP2 setup. <br/>I stalled some software (actually Blackberry Desktop Manager 4.0). <br/>Norton Antivirus complained that the install was about to mess with Windows. <br/>I allowed this (in retrospect, not good). <br/> <br/>Now, Windows won't stay up -- every time I reboot, it starts up, gets to a point where it's starting the services, then says "Can't start application because the windows station is shutting down". <br/> <br/>It does start and run in SAFE mode with networking. <br/>I have run Norton Antivirus (I have the latest LiveUpdated virus definitions). No virus found. <br/>I also found references to the possibility that my machine might have become infected with the Sasser Work or variation (on the Microsoft Windows XP support center site). Downloaded and ran both Symantec's and Microsoft Sasser Worm removal tools. Neither tool found any worm. <br/> <br/>So, at this point, it's highly unlikely that it's a known virus. Instead, my theory is that something has changed something in the c:\windows directory. <br/>Oh, and, also, reverting to a previous known-good system restore point was done successfully, but didn't fix the problem. So it's not a registry issue, but a base file issue. <br/> <br/>OK, any ideas? <br/> <br/>Tony
Posted 2/23/2005 9:40 PM
#10322
User avatar

TacoBelle Member

Date Joined Nov 2016
Total Posts: 3
I wonder if uninstalling the program that was installed before the error message started would help. I'm considering that myself. It doesn't always help, but it's possible. If you try it, let me know if it works! I can do without the programs I installed or buy a newer version.
Posted 9/3/2006 5:35 AM
#35834
User avatar

mell423 Member

Date Joined Nov 2016
Total Posts: 1
I'm having the same problem but a bit different. Whenever the computer shuts down or restarts I get the same message "the application has failed to initialize because windows is shutting down" but I havent recently installed anything to the computer to have caused the problem and just as everyone else said Ive ran virus software and no virus is found. I have no clue how to get rid of the message or what is causing it. Has anyone fixed this with their computer yet?? Thanks! :smile:
  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Wednesday, December 7, 2016, 3:31 PM (GMT +1)
There are a total of 61,160 posts in 13,449 threads.
In the last 3 days there were 0 new threads and 0 reply posts.

Who's online

This forum has 37,967 registered members. Please welcome our newest member, ConcepcionJAbbate.
There are currently no users on-line.