L
Luigi M Bianchi
As I was browsing the \winnt\system32, I clicked on fontview.exe, but
got an error (not a Windows executable). I did some research and found
that fontview.exe could also be a worm/virus (OPASERV.T). I checked the
filesize: 47376 and date: 11/06/2004 07:38. With a hex editor I
examined the file's internal version: 5.00.2195.6995 2.
.. Now, the original file in the w2k CD has, once expanded, a size of
38672 and a date of 11/30/1999 23:40, and is version 5.00.2134.1 2.
I went to
http://support.microsoft.com/dllhelp/?dlltype=file&l=55
&alpha=fontview.exe&S=1&x=12&y=8
and version 5.00.2195.6995 2 is not listed at all.
Is it possible that this version was installed by some MS update?
If not, and this forum's experts concur it is a worm, how do I get rid
of it?
Notes:
I run w2k sp4 with all the patches, including Jan 2007.
When I launch Fonts in control panel, everything is fine.
I tried to delete the file, both in \winnt\system32 and in \winnt
\system32\dellcache, but it gets re-created.
I have run AdAware and SpyBotSD, as well as F-Prot, and no malware was
found.
Thank you for your help.
/luigi
got an error (not a Windows executable). I did some research and found
that fontview.exe could also be a worm/virus (OPASERV.T). I checked the
filesize: 47376 and date: 11/06/2004 07:38. With a hex editor I
examined the file's internal version: 5.00.2195.6995 2.
.. Now, the original file in the w2k CD has, once expanded, a size of
38672 and a date of 11/30/1999 23:40, and is version 5.00.2134.1 2.
I went to
http://support.microsoft.com/dllhelp/?dlltype=file&l=55
&alpha=fontview.exe&S=1&x=12&y=8
and version 5.00.2195.6995 2 is not listed at all.
Is it possible that this version was installed by some MS update?
If not, and this forum's experts concur it is a worm, how do I get rid
of it?
Notes:
I run w2k sp4 with all the patches, including Jan 2007.
When I launch Fonts in control panel, everything is fine.
I tried to delete the file, both in \winnt\system32 and in \winnt
\system32\dellcache, but it gets re-created.
I have run AdAware and SpyBotSD, as well as F-Prot, and no malware was
found.
Thank you for your help.
/luigi