Now, I have downloaded all the video/audio codecs/packs that I can think of and I still had the same problems. I have upgraded WMP to number 10 to no affect and several other video players (after un-installing the old one) and this has not worked.
A virus! I thought so I have used several different methods until I came across this forum.
I have followed the 'before you post a Hijack this' page and got the needed programs. Have run all the proceedures and have the reports for you here...............
Logfile of HijackThis v1.99.1
Scan saved at 1:29:42 PM, on 19/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Useful progs\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.blueyonder.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\System32\rrkhydgi.dll
O2 - BHO: (no name) - {3875F1A9-7EA6-F00C-3847-074B957573C9} - C:\WINDOWS\System32\usadrdf.dll
O2 - BHO: (no name) - {42FBDFA3-9FC0-4C71-9E49-B82D111042FF} - C:\WINDOWS\System32\geedc.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....026/CTSUEng.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1158395637124
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.c...driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15026/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
and also this...................
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 16:21:28 19/10/2006
+ Scan result:
D:\System Volume Information\_restore{0934D21D-F840-489C-8BFE-F9370B186572}\RP166\A0058901.exe/{405D24E6-436A-46DB-8782-EC299DE4CBB8}.exe/clientax.dll -> Adware.180Solutions : No action taken.
C:\Documents and Settings\Prebble Family\My Documents\Luba\Application Data\rieabrfr.exe -> Adware.Lop : No action taken.
C:\Documents and Settings\Prebble Family\My Documents\Luba\Local Settings\Temporary Internet Files\Content.IE5\8TYRWX2Z\mp3_download[1].exe -> Adware.Lop : No action taken.
C:\Documents and Settings\Prebble Family\My Documents\Luba\Local Settings\Temporary Internet Files\Content.IE5\G1678HEJ\mp3[1].exe -> Adware.Lop : No action taken.
D:\System Volume Information\_restore{0934D21D-F840-489C-8BFE-F9370B186572}\RP182\A0083590.exe -> Adware.Lop : No action taken.
C:\System Volume Information\_restore{C6D28944-5EB1-4662-887E-ED88FC8A40FA}\RP142\A0040962.dll -> Adware.Searchcolours : No action taken.
C:\System Volume Information\_restore{C6D28944-5EB1-4662-887E-ED88FC8A40FA}\RP113\A0032844.exe -> Downloader.Small : No action taken.
D:\Useful progs\Iolo.System.Mechanic.Professional.v6.0u.WinALL.Incl.Keygen-ViRiLiTY\keygen.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\Prebble Family\My Documents\Luba\Local Settings\Temporary Internet Files\Content.IE5\G1678HEJ\exit01[1].htm -> Not-A-Virus.EmailFlooder.Win32.Merlin : No action taken.
C:\Documents and Settings\Prebble Family\Cookies\prebble family@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Prebble Family\My Documents\Luba\Local Settings\Temp\ICD1.tmp\30501031.exe -> Trojan.Dialer.en : No action taken.
C:\Documents and Settings\Prebble Family\My Documents\Luba\Local Settings\Temporary Internet Files\Content.IE5\SJJJEC55\30501031[2].cab/30501031.exe -> Trojan.Dialer.en : No action taken.
::Report end
Am doing the Panda virus scan as we talk
I hope this is of some use to you guys as I am at my wits end.