Chinese symbols in desktop.ini

G

Guest

Guest
I was just poking around on my system files, and I opened desktop.ini (on my desktop) and this is what I saw:


[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183
捉湯敒潳牵散䌽尺䥗䑎坏屓祳

Why are there chinese characters there? The last time I opened that file they weren't there.
I'd really appreciate any replies :)
 
Not sure, though I did run it through the translator->

Catch soup Zhentuqiansan䌽foot䥗䑎bad Xieshen

Probably not accurate.

I did Google and look for more information but couldn't find anything useful. Quick info:

1) that line is where my NVidia graphics card has a listing (maybe there's some video card correlation though I don't know what)

2) sometimes CORRUPTED files produce weird symbol strings

3) Try the following:
a) set a RESTORE POINT right now (google for how if you don't know)
b) run MALWAREBYTES free
c) DELETE the file and reboot (see if there)
d) maybe reinstall video drivers

there's probably more you can do, however if there are no issues and you can't find a virus I wouldn't worry too much about it
 
G

Guest

Guest
Thanks for the reply, I already do scheduled restore points, I ran MBAM, deleted the file and rebooted, and reinstalled my drivers; it didn't come back.
I'm still really eager on finding out what that was, tho. . .
 
G

Guest

Guest
Okay, it's happened! There are MORE chinese simbols! I only just checked, hang on, here you go:


[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183


捉湯敒潳牵散䌽尺䥗䑎坏屓祳瑳浥㈳獜敨汬㈳搮汬㐬ഹ嬊楖睥瑓瑡嵥਍潍敤ഽ嘊摩ഽ䘊汯敤呲灹㵥敇敮楲ൣ਍⹛桓汥䍬慬獳湉潦൝䰊捯污穩摥敒潳牵散慎敭䀽匥獹整剭潯╴獜獹整㍭尲桳汥㍬⸲汤ⱬ㈭㜱㤶਍捉湯敒潳牵散┽祓瑳浥潒瑯尥祳瑳浥㈳楜慭敧敲⹳汤ⱬㄭ㌸਍


What the hell is going on?!
I'm pretty sure it's not a virus, though. . .

Update: I've ran it through a translator:

Catch soup Zhentuqiansan䌽foot䥗䑎bad Xieshencuoyi ㈳ Lin Toujing ㈳ Lijing㐬ഹ Yanzhibilian Shijie ਍ Ai Wei Ke ഽ Mount ഽ䘊Hongkezizha㵥Cexia Wei Huan ൣ ਍⹛ Ji䍬Qinrutianlao ൝䰊Daowuwentang Zhenzha Qiansanshenyang SETUP POWER Fan Luzhengwuxun ╴ Linlu whole ㍭ Gan Benji ㍬⸲ soup ⱬ㈭㜱㤶਍ catch soup Zhentuqiansan ┽ cleanse wet luster of gems Yang Lang Liaoshencuoya ㈳ Huyinjiqiao ⹳ soup ⱬ ㄭ ㌸਍

"cleanse wet luster of gems"?! Either this is a HUGE coincidence, or somebody IS in fact writing random stuff into my desktop.ini!!
 
G

Guest

Guest
But I don't see any suspicious processes, and I don't see any ads at all! (Adblocker) My virus scanner can't find anything, nor did the two others I tried. This is really strange! :/
 
G

Guest

Guest
Alright, I just ran AdwCleaner; it found this stealth adware called "swdumon", which was apparently bundled with Slimware Driver Update (utterly useless SW, by the way). I'm removing it now.