Hi and thanks to everyone for taking the time to assist me with this problem.
Unfortunately, they have all failed thus far to make a difference to this
problem
Having tried every suggestion, i decided to to install HiJackThis.
On the initial was relatively boring and predictable, but on the MISC TOOLS
menu i decided to "Generate STARTUPLIST Log" with the "LIST MINOR SECTIONS"
checkbox checked.. it came up with sopmething interesting regarding
EXPLORER.EXE . The interesting part is about halfway down, regarding the
shell and registry entries... have a look... any suggestions for correcting
this would be greatly appreciated.
Thanks again.
StartupList report, 10/05/2006, 08:39:04
StartupList version: 1.52.2
Started from : F:\DOCUME~1\Bean\LOCALS~1\Temp\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Showing rarely important sections
==================================================
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Ahead\InCD\InCDsrv.exe
F:\WINDOWS\system32\spoolsv.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\svchost.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
F:\Program Files\Ahead\InCD\InCD.exe
F:\WINDOWS\SOUNDMAN.EXE
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
F:\Program Files\MSN Messenger\MsnMsgr.Exe
F:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\DOCUME~1\Bean\LOCALS~1\Temp\HijackThis.exe
F:\WINDOWS\system32\NOTEPAD.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[F:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LDMConf.exe
Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = F:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
TkBellExe = "F:\Program Files\Common Files\Real\Update_OB\realsched.exe"
-osboot
SunJavaUpdateSched = F:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
QuickTime Task = "F:\Program Files\QuickTime\qttask.exe" -atboottime
Logitech Hardware Abstraction Layer = KHALMNPR.EXE
InCD = F:\Program Files\Ahead\InCD\InCD.exe
SoundMan = SOUNDMAN.EXE
NvMediaCenter = RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
nTrayFw = F:\Program Files\NVIDIA
Corporation\NetworkAccessManager\bin\nTrayFw.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
msnmsgr = "F:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
LDM = F:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger.exe
Windows Registry Repair Pro = F:\Program Files\3B Software\Windows Registry
Repair Pro\RegistryRepairPro.exe 4
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = F:\WINDOWS\inf\unregmp2.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall
%SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE
/CALLER:WINNT /user /install
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB
/CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe
[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = F:\WINDOWS\system32\Rundll32.exe
F:\WINDOWS\system32\mscories.dll,Install
--------------------------------------------------
Shell & screensaver key from F:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Checking for EXPLORER.EXE instances:
F:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
F:\WINDOWS\Explorer\Explorer.exe: not present
F:\WINDOWS\System\Explorer.exe: not present
F:\WINDOWS\System32\Explorer.exe: not present
F:\WINDOWS\Command\Explorer.exe: not present
F:\WINDOWS\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - F:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll -
{02478D38-C3F9-4EFB-9B51-7695ECA05670}
(no name) - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll -
{53707962-6F74-2D53-2644-206D7942484F}
(no name) - F:\Program Files\Java\jre1.5.0_06\bin\ssv.dll -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - F:\Program Files\Common Files\Microsoft Shared\Windows
Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
--------------------------------------------------
Enumerating Download Program Files:
[QuickTime Object]
InProcServer32 = F:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE =
http://www.apple.com/qtactivex/qtplugin.cab
[Windows Genuine Advantage Validation Tool]
InProcServer32 = F:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE =
http://go.microsoft.com/fwlink/?linkid=39204
[MUWebControl Class]
InProcServer32 = F:\WINDOWS\system32\muweb.dll
CODEBASE =
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147014114343
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: F:\WINDOWS\system32\pnrpnsp.dll
NameSpace #2: F:\WINDOWS\system32\pnrpnsp.dll
Protocol #1: F:\WINDOWS\system32\nvappfilter.dll
Protocol #2: F:\WINDOWS\system32\nvappfilter.dll
Protocol #3: F:\WINDOWS\system32\nvappfilter.dll
Protocol #4: F:\WINDOWS\system32\nvappfilter.dll
Protocol #5: F:\WINDOWS\system32\nvappfilter.dll
Protocol #6: F:\WINDOWS\system32\nvappfilter.dll
Protocol #7: F:\WINDOWS\system32\nvappfilter.dll
Protocol #8: F:\WINDOWS\system32\nvappfilter.dll
Protocol #9: F:\WINDOWS\system32\nvappfilter.dll
Protocol #10: F:\WINDOWS\system32\nvappfilter.dll
Protocol #11: F:\WINDOWS\system32\nvappfilter.dll
Protocol #12: F:\WINDOWS\system32\nvappfilter.dll
Protocol #13: F:\WINDOWS\system32\nvappfilter.dll
Protocol #14: F:\WINDOWS\system32\nvappfilter.dll
Protocol #15: F:\WINDOWS\system32\nvappfilter.dll
Protocol #16: F:\WINDOWS\system32\nvappfilter.dll
Protocol #17: F:\WINDOWS\system32\nvappfilter.dll
Protocol #35: F:\WINDOWS\system32\nvappfilter.dll
--------------------------------------------------
Enumerating Windows NT/2000/XP services
ASInsHelp: \??\F:\WINDOWS\system32\drivers\AsInsHelp32.sys (autostart)
Aspi32: System32\drivers\aspi32.sys (autostart)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
AVG7 Alert Manager Server: F:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
(autostart)
AVG7 Update Service: F:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
AVG E-mail Scanner: F:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (autostart)
AVG Network Redirector: \SystemRoot\System32\Drivers\avgtdi.sys (autostart)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs
(autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch
(autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs
(autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
ForceWare Intelligent Application Manager (IAM): F:\Program Files\NVIDIA
Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe (autostart)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
InCD Helper: F:\Program Files\Ahead\InCD\InCDsrv.exe (autostart)
RIP Listener: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService
(autostart)
ForceWare IP service: F:\Program Files\NVIDIA
Corporation\NetworkAccessManager\bin\nSvcIp.exe (autostart)
ForceWare user log service: F:\Program Files\NVIDIA
Corporation\NetworkAccessManager\bin\nSvcLog.exe (autostart)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss
(autostart)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs
(autostart)
Windows Firewall/Internet Connection Sharing (ICS):