i posted below about my adwaheck trojan.. and my notepad probs. now i'm wondering if i have something else entirely.
i've spent the past few hours *tinkering*. it appears that this fake(?) notepad.exe file in c:\windows\system32 extracts itself when run (by attempting to run notepad via any shortcut) into what norton pointed out to be the adwaheck trojan. eachtime you run it it takes a different file name (i've ran system restore quite a few times :) and tried it)
now for what appears to get worse (or maybe i just don't know enough about xp) but if i run system tools sytem info and have if show me a history of changes there is a zillion changes timed and dated aprox when i started the program. nasty scarry looking stuff.. changing filenames.. manafacturers..users..versions.. device memory addresses. you name it. at the point i freaked and ran system restore (for the first time).
it appears it's not as simple as deleting a file and what it puts in the registry. i deleted the fake(?) noteepad right after system restore then emptied recycle bin.. never ran notepad but still had the problems in system info.
has anyone expirenced anything like this with their dissapearing notepad programs?
any fixes?
thanks