- WJView Error
- Posted by Dana Krug on January 17th, 2004
I just had a bout with a virus. After removing the infected files with
Norton, I now get "WJView Error: could not execute main; the system cannot
find the specified file" Help?
- Posted by °Mike° on January 17th, 2004
When you start Windows XP, you receive 'WJView error - Could
not execute main'
http://www.jsiinc.com/SUBP/tip7600/rh7627.htm
On Sat, 17 Jan 2004 19:18:05 GMT, in
<NTfOb.56009$6y6.1133829@bgtnsc05-news.ops.worldnet.att.net>
Dana Krug scrawled:
--
Basic computer maintenance
http://uk.geocities.com/personel44/maintenance.html
- Posted by Dana Krug on January 17th, 2004
thanks!
<Harrison> wrote in message
news
q2j00hki6kls7l1a5cg63cpeii91c831m@4ax.com...
- Posted by Dana Krug on January 17th, 2004
Okay, now I'm stumped. I went through each step to try an remove the files
manually, of course to no avail. Since none of the specified files were
found, I downloaded SpyHunter v1.5.81 see if maybe it could remove the
files. Again...no. Is there some other way to do this?
thanks....
"Dana Krug" <cletusnbeuhla@worldnet.att.net> wrote in message
news:w%fOb.26479$VS4.819179@bgtnsc04-news.ops.worldnet.att.net...
- Posted by Dana Krug on January 18th, 2004
It wasn't a "virus" but a high-risk file that Norton had detected - three
files were deleted/three quarantined. My operating system is Windows XP
home edition.
<Harrison> wrote in message
news:k2mj00t36h4pi53bq6h06s6ouhcu37mner@4ax.com...
- Posted by Dana Krug on January 18th, 2004
I found the WJVIEW.exe, but not under the directory as stated in the the
tips. I assume that it is okay to delete the wjview.exe without any
repercussions?
"°Mike°" <ZHNTPDWBLECA@fcnzzbgry.pbz> wrote in message
news:40118be2.20046515@localhost.dot.net...
- Posted by °Mike° on January 18th, 2004
"Exit stage left."
On Sat, 17 Jan 2004 22:28:57 -0500, in
<r0vj00db5jo2q8rfcv1ov0fvv7aelgls03@4ax.com>
Harrison scrawled:
--
Basic computer maintenance
http://uk.geocities.com/personel44/maintenance.html
- Posted by °Mike° on January 18th, 2004
Don't you read instructions? Nowhere does it say to
delete the file, only the startup entry box/es.
On Sun, 18 Jan 2004 03:35:25 GMT, in
<1anOb.58392$6y6.1178109@bgtnsc05-news.ops.worldnet.att.net>
Dana Krug scrawled:
--
Basic computer maintenance
http://uk.geocities.com/personel44/maintenance.html
- Posted by Dana Krug on January 18th, 2004
yes, I read the instructions and NO there was no box to check under the
directory stated
"°Mike°" <ZHNTPDWBLECA@fcnzzbgry.pbz> wrote in message
news:40130021.3226437@localhost.dot.net...
- Posted by Dana Krug on January 18th, 2004
also, on the instructions it said to "delete any value name whose data value
contains a reference to WJVIEW.exe - wouldn't you have thought to delete the
file?
"Dana Krug" <cletusnbeuhla@worldnet.att.net> wrote in message
news:zLnOb.27947$VS4.874523@bgtnsc04-news.ops.worldnet.att.net...
- Posted by °Mike° on January 18th, 2004
No, not at all. How can you confuse "delete any value name whose
value contains a reference to", with "delete the FILE"?
Dana, install HijackThis and post the contents of the log
it provides, here.
HijackThis
http://www.tomcoyote.org/hjt/
On Sun, 18 Jan 2004 04:18:29 GMT, in
<pOnOb.27954$VS4.875307@bgtnsc04-news.ops.worldnet.att.net>
Dana Krug scrawled:
<snip>
--
Basic computer maintenance
http://uk.geocities.com/personel44/maintenance.html
- Posted by Dana Krug on January 20th, 2004
Here are the results of the Norton scan of 1/16. Scan on 1/20 didn't show
anything.
"quarantined":
gatorpdplugin.og - threat name unknown
gatorpdpsetup.log - threat name unknown
gatorplugin.log - threat name unknown
back up of deleted risks:
main.class - adware.topmoxie - backup of deleted security risk - file type
is "adware"
msmgt.exe - adware.memorymeter - " " "" - file type is "adware
Hijackthis log results:
Logfile of HijackThis v1.97.7
Scan saved at 3:28:40 PM, on 1/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\XdriveNT\xdService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\AT&T\DSL\programs\dslpca.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\efax\HotTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Common Files\efax\Dllcmd32.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Dana Krug\My Documents\Applications\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.worldnet.att.net/ie4/search/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.dogpile.com/info.dogpl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://attdslservice.att.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.earthlink.net/partner/mor...on/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.dogpile.com/info.dogpl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.att.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.earthlink.net/partner/mor...on/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
Internet Explorer provided by AT&T WorldNet Service
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.dogpile.com/info.dogpl.toolbar/
R3 - URLSearchHook: CleverHook Class -
{707E6F76-9FFB-4920-A976-EA101271BC25} - C:\WINDOWS\jeired.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} -
C:\WINDOWS\jeired.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program
Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
C:\WINDOWS\Downloaded Program Files\googlenav.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program
Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [MyPointsPointAlert] wjview /cp
"C:\Program
Files\MyPointsPointAlert\System\Code" Main lp: "C:\Program
Files\MyPointsPointAlert"
O4 - HKLM\..\Run: [AT&T DSL Service PCA Program] C:\Program
Files\AT&T\DSL\programs\dslpca.exe /ws
O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program
Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ESFTP] C:\Program Files\ESFTP\esftp.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common
Files\efax\HotTray.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program
Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common
Files\efax\Dllcmd32.exe
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O8 - Extra context menu item: MyPoints - file://C:\Program
Files\MyPointsPointAlert\System\Temp\mypoints_scri pt0.htm
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: Point Alert (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.att.net
O16 - DPF: {05CE4481-8015-11D3-9811-C4DA9F000000} -
http://www.topmoxie.com/external/bui...ve/IGmoxie.cab
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal
Account Registration) -
https://secure.stamps.com/download/u...5/sdcregie.cab
O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} -
http://www.stop-sign.com/pub/download/scandl_cnry.cab
O16 - DPF: {22E5705C-991A-4646-9053-A9525CA7222A} -
http://www.topmoxie.com/external/bui...ts/mpmoxie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus
scanner) -
http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://download.yahoo.com/dl/installs/yinstc.cab
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX
Plug-in) - http://www.imgag.com/cp/install/AxCtp.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) -
http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/08564f9a2e22168...E601Arcade.cab
O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349} (Pixami/Snapfish Upload UI
Control) - http://www.snapfish.com/SnapfishUploader.cab
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} -
http://a1040.g.akamai.net/f/1040/759...nload/tbar.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) -
http://toolbar.google.com/data/en/de.../GoogleNav.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload
Control) - http://sc.communities.msn.com/contro...UC/MsnUpld.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.co...845.4620486111
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} (SDCInstaller Class) -
http://www.stamps.com/download/us/ca...ile=stamps.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer
Control) -
http://crystal.petplace.com/viewers/...ivexviewer.cab
O16 - DPF: {C72242D0-3AB5-453D-842C-8A3C9AC0838D} -
http://download.sidestep.com/get/k00719/sb027.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on
the Web Control) -
http://officeupdate.microsoft.com/Te...loads/outc.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl
Class) - http://picturecenter.kodak.com/activ...oadControl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/is...07/mcfscan.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} -
http://www.trueswitch.com/att/TrueInstallATT.exe
O17 -
HKLM\System\CCS\Services\Tcpip\..\{74057966-14E7-4669-B3E5-D003DB574332}:
NameServer = 64.105.172.26 64.105.163.106