DVD Talk Forum

DVD Talk Forum (https://forum.dvdtalk.com/)
-   Tech Talk (https://forum.dvdtalk.com/tech-talk-10/)
-   -   Windows can't find Notepad (https://forum.dvdtalk.com/tech-talk/376201-windows-cant-find-notepad.html)

Mongo 07-22-04 05:51 PM

Windows can't find Notepad
Windows XP (home) can no longer find notepad when I try to open it, yet it's still in the default directory (C:\Windows)

The only irregularity that I can find, but not sure if it actually is irregular, that under the shortcut properties, the info for "Starts In" field is set to "%HOMEDRIVE%%HOMEPATH%"

sfsdfd 07-22-04 06:02 PM

Screw that. You should be using Wordpad anyway. ;)

Just change the shortcut to c:\windows\notepad.exe and you're golden.

- David Stein

Mongo 07-22-04 06:12 PM

I changed it to C:\Windows and it works ok now.

The target was correct ..\notepad.exe, it was the "starts in" field that had the variables. The weird thing is I use notepad all time, so no idea how or why it got changed.

X 07-22-04 07:00 PM

Your "start in" should have been fine. However your target should be "%SystemRoot%\system32\notepad.exe" and Notepad.exe should be in \Windows\system32. Unless the Home version of XP is different than Pro, but I doubt it.

twikoff 07-22-04 07:15 PM

and stop screwing with your environment variables


68ShelbyGT500KR 07-22-04 07:51 PM

Info on Notepad
Located in:
Windows 95: C:\WINDOWS
Windows 95/98/98SE/ME: C:\WINDOWS
Windows NT4/2000: C:\WINNT and C:\WINNT\System32
Windows XP: C:\WINDOWS and C:\WINDOWS\System32
Deleted by: CWS.Googlems.
Purpose: Notepad application executable, required to run it.
Symptoms: Error messages 'Cannot find file NOTEPAD.EXE' or 'NOTEPAD.EXE' is not a valid Win32 application'.

Run CWShredder to confirm it has not been tampered by a variant

and run HijackThis and post the contents of the log here

BigPete 07-22-04 09:13 PM

You have spyware, chief. Could be CWS or it could be something more devilish. It took me the better part of 3 hours to clean up last time that one got me because it also hijaacked media player and forged a couple dlls which screwed ie. Have fun.

Mongo 07-22-04 11:13 PM

Argh, no damnit!

Spent 2 months trying to get rid of some other spyware crap I had on here, don't tell me I'm infected again.

I know some of them do something to notepad, but..but...ahh, crap. Ok, off to run Hijack this again, as well as others.

68ShelbyGT500KR 07-22-04 11:19 PM

Originally posted by Mongo
Argh, no damnit!

Spent 2 months trying to get rid of some other spyware crap I had on here, don't tell me I'm infected again.

I know some of them do something to notepad, but..but...ahh, crap. Ok, off to run Hijack this again, as well as others.

We are not telling you that you do have any spyware, but if you post your log, We will try to help you to determine if you have anything suspicious.
What browser do you use?
Do you use any Protection? If so, what programs and/or methods.

Mongo 07-22-04 11:50 PM

I regularly run AdAware and Spybot (and update them each time I run them, at least 1x/week.)

Anyway, I also just ran CWSshredder (clean) and HiJackThis!. AdAware came back with a clean scan except for a few tracking cookies.

Here's my HijackThis! log.

Logfile of HijackThis v1.97.7
Scan saved at 10:45:57 PM, on 7/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\UltimateBuddy\UltimateBuddy.exe
C:\Documents and Settings\Michael Clark\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {8C918A35-0240-4685-B486-23B226536056} - C:\WINDOWS\_MWCTB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Merriam-Webster Collegiate - {E9903977-FFCE-4827-A9D7-A325A0F87F18} - C:\WINDOWS\_MWCTB.DLL
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [mp4sdmod] C:\WINDOWS\System32\mp4sdmod.exe
O8 - Extra context menu item: &Spanish-English Dictionary - res://C:\WINDOWS\_MWCTB.DLL/23/237
O8 - Extra context menu item: Collegiate &Dictionary - res://C:\WINDOWS\_MWCTB.DLL/23/219
O8 - Extra context menu item: Collegiate &Encyclopedia - res://C:\WINDOWS\_MWCTB.DLL/23/236
O8 - Extra context menu item: Collegiate &Thesaurus - res://C:\WINDOWS\_MWCTB.DLL/23/220
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it0_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/game...ts/y/tt2_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/download/tgctlcm.cab
O16 - DPF: {12F7F128-B36C-4843-8AA4-A5F71A969331} (Launcher Control) - https://horizons.istaria.com/controls/launcher.ocx
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho.../yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_44.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/ca...ail/DASAct.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://everquest2.station.sony.com/b...soesysinfo.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D4E3D5D9-9959-482D-9D5A-C74880E7FB74} (Merriam-Webster Unabridged Toolbar) - http://www.merriam-webstercollegiate...webinstall.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/28...CX/FlashAX.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

68ShelbyGT500KR 07-23-04 07:30 PM

Run Hijack this and let it fix this "R3" item. Otherwise your system looks good!
R3 - Default URLSearchHook is missing
Re-Run Hijackthis after you let it lix the R3 item to make sure it is gone for good.

These are my recommended freeware detectors,monitors, and/or removers:

You may want to consider to try FireFox, Mozilla or anything not IE or a shell of IE related.
Essential Spyware, Hijacking prevention/monitoring tools:
Adaware 6.181 with current reference file
BHO Demon 2.0
Use a HostFile (I think SW Guard includes this in the program)
A registry/startup Monitor like regprot

All times are GMT -5. The time now is 09:46 PM.

Copyright 2018 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.