I have discovered that my registry contained the following:
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\AutoRun

and/or

HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun

which pointed to cmd.exe! thus cmd.exe was executing itself whenever it started!

To read up on this functionality, run cmd.exe /? on a good machine and see the use of the /D switch.

It appears that either Spybot accidentally inserted this, or the malware that spybot was removing did so. Anyway... no blame folks.