Based on the dates of my posts on geekstogo, my pc was 'cleansed' of a major problem around 25 September 2010.
The Autoruns report showed this under 'Image Hijacks':-
September 2010
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" "" "" ""
+ "Your Image File Name Here without a path" "Symbolic Debugger for Windows 2000" "Microsoft Corporation" "c:\windows\system32\ntsd.exe"
..which I believe was ok. Not sure what happened afterwards, but it changed to:-
9 November 2010
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" "" "" ""
+ "Your Image File Name Here without a path" "" "" "File not found: kîOw„û”8ðOw´w"
When pasted into Google, it looked like this: kîOw„û”
A list of sites did appear, all with weird symbols (including my one) in their listings!
Here's another example:-
11 November 2010
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" "" "" ""
+ "Your Image File Name Here without a path" "" "" "File not found: ƕ器ƕ愈ƕ粐Ȩ粑
Google's response was: 'Your search - ï¡„Æ•ï¨¸Æ•ïªˆÆ•î¤ ç² È©ç²‘ï¿¿ - did not match any documents.'
This Autorun entry still haunts me!
Today when I ran AR, there was '1/4' (a quarter symbol) at the end (wish I had taken a screenshot ), but it didn't show up in the text file here:-
17 July 2011 (today)
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options" "" "" ""
+ "Your Image File Name Here without a path" "" "" "File not found: Ɨ器Ɨ愈Ɨ粐Ȩ粑
The strange thing is, when I used the Autoruns compare option, the entry showed in green: I believe this means that the entry had changed somehow, but I can't see where or how! (Sadly, I often forget to save as both .arn AND .txt files so April was my last saved text report to compare!)
I'm baffled.
I have Googled it a few times, but discovered very little - maybe perl language or something (doh?) If so, why?
On my pc, everything seems to be running fine so I'm not overly worried - yet!
I just know it's not quite right and it's niggling away at me! (Hmm.. had that feeling before did I not.. just before I joined geekstogo in fact! hmmm)
Ahem. Paranoia aside, what do you think? Should I worry?
Thanks in advance.