The Mudcat Café TM
Thread #95880   Message #1869220
Posted By: JohnInKansas
26-Oct-06 - 12:50 PM
Thread Name: Tech. Strange message. Is it safe etc?
Subject: RE: Tech. Strange message. Is it safe etc?
Win98 is somewhat prone to Kernel32.dll corruption, as outlined in Microsoft Knowledge Base article 190517: Troubleshooting Office Kernel32.dll errors under Windows 98. Usually, however, the messages you'd get would refer to a "page fault" or some other "error" notice.

The message you're getting is just a "status" notice, probably from your firewall. It indicates that the Kernel32.dll "program file" is attempting to do something that's its normal function, but your firewall doesn't think it's safe.(?)

If you have a router connected in your setup, and your router uses the 224.0.0.2 address, it's possible it's a normal attempt to connect, but you need to know what's trying to connect and for what purpose. The message indicates that "something" on your machine is attempting to connect to the internet. If you don't have a program that's supposed to be checking in, it most likely is malware.

AVG has one of the better reputations for consistent performance among the free AV programs. If updated to the latest signatures it should catch any likely virus.

As Amos suggested, it may be a virus trying to spread itself, but since it's asking for a "port" rather than just using your email, it's more likely that you've picked up a "bot" program that's trying to tell it's "master" that it's there so that other nasty stuff can be downloaded to your machine.

Unfortunately, most such "bots" are NOT VIRUSES. They get on your machine because you opened an email, or clicked something on a website, with the malicious item being rigged to make it look like you gave "permission" to install a program. Especially with Win98, it's also possible that someone "just passing by" noticed you had open connections and dumped something on your machine.

If you have a port open, your Firewall probably thinks you opened it on purpose so it may let someone talk to your machine through that port; and Win98 isn't very good about keeping things locked up tight.

(If you've downloaded any new "music sharing," tool bars, "computer speed-ups" or other even slightly questionable junk in the something-for-nothing category – i.e. not from a known and trusted source - odds are about 7 out of 9 that any such program includes malware.)

Once such a program is on your machine, it's "just another program," and it no longer looks like a virus, and your AV may not be able to detect it.

AVG, like most AV programs, has attempted to incorporate some recognition of bots and other spyware/malware, but the protection you get from the free programs is limited.

You should try:

1. Because corrupted temp space can sometimes cause kernel32.dll problems, especially in Win98, you should try clearing all your browser temp space. The KB article linked above includes a section " Check for a Valid Temporary Folder and Excess Temporary Files" that gives instructions for Win98. You may want to read the rest of the article for other hints, since you'll know more than we do about what's on your machine that might apply.

2. Update your AntiVirus and run a full scan.

3. If you don't already have it, get AdAware SE and run a full scan. Note that after you donwload AdAware SE, you do need to check for updates to it's signature files before running the scan.

4. If you don't already have it, get Spybot S&D and run a full scan. The same requirement – check for updates after you download it, before doing the scan – applies here as well.

The last (trusted) sites I have in my notes where you could get the above two (free) programs were:

Ad-Aware

(http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10045910.html?part=dl-ad-aware&subj=dl&tag=top5)

Spybot S&D (http://www.safer-networking.org/en/download/index.html)

These should still be good, but if not you can Google and find several places where they're available.

There may be a completely "innocent" explanation for the message you're getting, since it really only indicates that "something" is trying to connect. There are a number of legitimate reasons why something on your machine may be supposed to do so, but anytime you get something "new and different" happening you have to expect that something's gotten to you.

You should run through at least the above steps to be reasonably assured that you haven't picked up some malware before you relax though. They can't guarantee you're clean; but for most of the common crud they're pretty effective.

And when you have time to relax, think seriously about getting something a little more current than Win98, if at all possible.

John