One of my XP systems is now opening the "system32" folder each time someone logs into the local computer. I have checked for virus infection, ran spybot and adaware, and ran hijackThis on it but cannot figure out what is causing this. I have also tried the #260 tip listed in other threads but that runs and says there is no entry of that type in registry. I have checked the registry RUN commands but have no strange entries there. I have disabled everything in the MSCONFIG startup items and that does not help either.
Here is the info I copied from HijackThis...
StartupList report, 6/22/2006, 2:43:01 PM
StartupList version: 1.52.2
Started from : C:\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==========================
==========
==========
====
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
C:\WINDOWS\system32\cisvc.
exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe
C:\WINDOWS\system32\ctfmon
.exe
C:\HijackThis.exe
--------------------------
----------
----------
----
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
indows NT\CurrentVersion\Winlogon
]
UserInit = C:\WINDOWS\system32\userin
it.exe,
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe /STARTUP
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnceEx
(Default) =
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon
.exe
--------------------------
----------
----------
----
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\Sy
stem32\log
on.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
----------
----------
----
Enumerating Browser Helper Objects:
(no name) - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll - {53707962-6F74-2D53-2644-2
06D7942484
F}
--------------------------
----------
----------
----
Enumerating Task Scheduler jobs:
Norton Internet Security.job
Symantec NetDetect.job
--------------------------
----------
----------
----
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macrom
ed\Flash\F
lash8b.ocx
CODEBASE =
http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab--------------------------
----------
----------
----
Enumerating ShellServiceObjectDelayLoa
d items:
PostBootReminder: C:\WINDOWS\system32\SHELL3
2.dll
CDBurn: C:\WINDOWS\system32\SHELL3
2.dll
WebCheck: *Registry key not found*
SysTray: C:\WINDOWS\System32\stobje
ct.dll
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\policies\
Explorer\R
un
wininet.dll =
kernel32.dll = C:\WINDOWS\system32\