Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Here is the pop-up window I get.
"AVG Resident Shield
Trojan horse Downloader.Revop.Ais found in file
c:\System Volume Information\_restore{0765...A0065877.exeTo remove this virus, please run AVG for Windows
[OK]"However, AVG will not remove the virus. I looked for that folder, and c:\System Volume Information\ does not exist! (visibly). I have search the internet a lot, and found that maybe it is in my system restore files, but is my only option here to turn off my system restore and then turn it back on again? Thus, deleting ALL of my restore points? Also, is this nessesary, can the virus get out of that file into the rest of the coputer? Thanks so much. and it'd be great if somebody coudl email me back with a reply as well as post it on this site!
thanks!thescottrock@yahoo.com

Can the virus get out of restore?
Yes if you restore PC to an earlier time.
If you don't restore, I don't know that one.I don't know of any other way to clear restore without clearing all the restore points (as you say).
Restore is a protected area, so I don't think any program will get in there to delete just this virus and leave the rest as is.
Lastly, if you leave your E-mail visible for all to see, you might get spam and other unwanted crap.

HI ! as i have just found out, if you are using a fat32 file system you can open the system restore folder and delete the offending file without losing your restore points,you must put another (safe) file in its place with the same name. This is not possible with an ntfs file system ! to view this folder you need to show your hidden files. open a folder click tools, click folder options, click view, then check the "show hidden files and folders" option also it is wise to uncheck the "hide extentions for known file types" so you dont get fooled by double extentions eg, mypic.jpg.exe as for showing your email addy to the whole world dont worry just get yourself a few email addys and one that you dont mind getting full of junk ! RsPcT> LYNX32!!"" rayus.2@lycos.co.uk

I have just looked in system restore folder and all the stuff is in code. I don't think the idea suggested by Response Number 3 would work. I have not looked in that folder before, even though I do have hidden stuff showing for the very reason.....mypic.jpg.exe
'how do i scrap my email off of there'?...
There are bots that search the net for E-mail addresses, to send spam to.
E-mail one of the moderators and tell them how good this site is, then ask nicely.

Hi - I'm running Windows 98 and don't have system restore. I got rid of Revop but every time I boot up I get "looking for missing shortcuts" Aregon and loads of strings of rubbish, then I get fatal error message but machine comes on OK and seems to be alright, just drives me mad having to click through all the start up messages, I've no idea how to fix this as am new to all this, any help gratefully received, thanks.

Scott
It is best to disable the system restore, reboot, if all clean according to AVG then you can turn on system restore again.
Yes that action will remove all restore points but a new one will be made when you re-enable it again.
As said above the virus can get out of sys restore if you restore the system using the infected restore point.
It cannot get out if you dont use it.
You will find it annoying every time your computer makes its restore points automatically AVG will pop up flagging the virus in there (because windows has that folder open)
As said above windows locks that folder from any programs (or us) from modifying it including antivirus.
You can add yourself as a user with full access to system restore and have access to that folder but not recommended because if you delete the infected file from that restore point...then need it...the restore will be incomplete with obviously undesired or unrecoverable concequences.
I also wouldn't recommend using a restore point say from 2 months ago because it would mean any av updates, windows updates, newly added programs, etc would need re-doing.
I clean out restore on a regular basis so I always have a fresh one. (less fixing to do later if I ever need it)I never give up!

I haven't got system restore, is there anything else I can do? I've had Revop A, B and now D and I keep getting missing shortcut notices when I boot up plus fatal error then illegal action or something, it's driving me crazy - I have windows 98, thanks

Your support forum seems to talk more sense than others. Thank you. The Trojan Scans suggested by Starwaves and Justin don't seem to know Revop - although I found it on Sophos who recommended using their AV first. My PC won't work with Sophos; I've tried it. I now use Panda which found and deleted Revop variants A, B. and C., i.e. over.exe, pup.exe and do.exe. But the popups (some quite offensive) persist every time an IE window is opened. IE also crashed again last evening as I was writing this...this is 2nd time lucky. Popup Stopper Professional will zap only the first popup on opening, and it seems disabled after that. Spybot is useful to keep Spyware (introduced I surmise by our friend Revop) at bay, but that too reasserts itself after a time.
I have painstaking collected all offending urls and put them on the preferences 'Blocked' list but to no avail.Problems on startup occurred after Panda had located and disinfected all three variants. AOL kept attempting to launch before the MS office tool bar and the tray icons had loaded, including of course the Popup stopper/spyware. The messages received at the same time, alternating attempts, are : Could not load or run 'Program' file specified in the WIN.INI file. Make sure the file exists or remove ref to it in the WIN.INI file. Also 'Could not find the file 'Windows' or one of its components...' etc. The first sounded easy, but when I located WIN.INI, there was a great long string at the beginning which doesn't look very likely. Here it is: where the problem liesI think --
[windows]
load=
run=C:\Program Files\AOL 7.0b\hpfsched.bat;C:\Program Files\AOL 7.0b\hpfsched.exe;C:\Program Files\AOL 7.0b\hpfsched.com;C:\Program Files\AOL 7.0b\hpfsched.scr;C:\Program Files\AOL 7.0b\hpfsched.vbs;C:\WINDOWS\hpfsched.bat;C:\WINDOWS\hpfsched.exe;C:\WINDOWS\hpfsched.com;C:\WINDOWS\hpfsched.scr;C:\WINDOWS\hpfsched.vbs;C:\WINDOWS\COMMAND\hpfsched.bat;C:\WINDOWS\COMMAND\hpfsched.exe;C:\WINDOWS\COMMAND\hpfsched.com;C:\WINDOWS\COMMAND\hpfsched.scr;C:\WINDOWS\COMMAND\hpfsched.vbs;C:\WINDOWS\SYSTEM\hpfsched.bat;C:\WINDOWS\SYSTEM\hpfsched.exe;C:\WINDOWS\SYSTEM\hpfsched.com;C:\WINDOWS\SYSTEM\hpfsched.scr;C:\WINDOWS\SYSTEM\hpfsched.vbs
NullPort=None
device=HP DeskJet 930C Series,hpf9xdr0,LPT1:Problem is I don't know what it should look like, and don't want to delete anything till I know.....
Not so bad as Lisa's prob. but my PC does seem to be targeted by a remote attacker, which is scary.
Thanks in advance for any advice.

Lorna
You are right ...that run line definately is not right...
The run line should look like this:
run=
But since you have a deskjet printer it should look like the next one I have typed.
run=hpfsched.exe
Before you fix it...what operating system are you running?
I also think there are other problems....I have never seen a run line like that.I think we better look at things from a different angle.
Download HijackThis from here: (direct download)
Download it to its own folder (not a temp folder or the desktop) because it makes backups on what is fixed.
Once downloaded, double click to start.
Click "scan"
Scan button changes to "save log" button
Click save log, click save.
It will open up in notepad;
Copy/paste entire log here.
Don't fix anything yet...most of what you see in the scan is safe or even essential!In case you are wondering..hijackthis shows what is starting up with windows....good and bad, what is installed with Internet Explorer, Installed active x controls, running processes etc. It makes it easier to analyse the problem(s).
________________________________________I never give up!

Thanks, Blender. Op System - Windows 98SE.
64MB RAM. I have a bit of Hard disk left - 2.02 GB (of 5.58) Here is the HijackThis Log as yu requested. Apologies to others for taking up a lot of space...I take your point about the MS updates. Do I bother with those that say 98 as opposd 98SE? There are 20 upgrades listed, which would take up a lotta memory.Logfile of HijackThis v1.97.7
Scan saved at 22:43:20, on 17/03/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\PROGRAM FILES\COMMON FILES\SYSTEM\MOSEARCH\BIN\MOSEARCH.exe
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\PSTORES.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\IOMEGA\DRIVEICONS\IMGICON.exe
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.exe
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\CTFMON.exe
C:\WINDOWS\RUNDLL32.exe
C:\WINDOWS\MSLAGENT\MSLAGENT_.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.exe
C:\PROGRAM FILES\PANICWARE\POP-UP SCANNER\POPUPSCN.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PROFESSIONAL\POPUPSTOPPERPROFESSIONAL.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE10\MSOFFICE.exe
C:\COREL\SUITE8\PROGRAMS\WPWIN8.exe
C:\PROGRAM FILES\HIJACKTHIS.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
F1 - win.ini: run=C:\Program Files\AOL 7.0b\hpfsched.bat;C:\Program Files\AOL 7.0b\hpfsched.exe;C:\Program Files\AOL 7.0b\hpfsched.com;C:\Program Files\AOL 7.0b\hpfsched.scr;C:\Program Files\AOL 7.0b\hpfsched.vbs;C:\WINDOWS\hpfsched.bat;C:\WINDOWS\hpfsched.exe;C:\WINDOWS\
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {DE614603-6320-4046-A7A7-6A69CEC26F14} - C:\WINDOWS\MSLAGENT\4B_1,0,0,6_MSLAGENT.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\SYSTEM\MOSEARCH\BIN\MOSEARCH.exe
O4 - HKLM\..\RunServices: [MDM7] "C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1034.dll,InstantAccess
O4 - HKCU\..\Run: [mslagent] C:\WINDOWS\mslagent\MSLAGENT_.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.exe"
O4 - HKCU\..\Run: [Pop-Up_Scanner] "C:\PROGRAM FILES\PANICWARE\POP-UP SCANNER\POPUPSCN.exe"
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PROFESSIONAL\POPUPSTOPPERPROFESSIONAL.exe"
O4 - Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0b\aoltray.exe
O4 - Startup: Microsoft Office.lnk = C:\WINDOWS\Application Data\Microsoft\Installer\{90190409-6000-11D3-8CFE-0050048383C9}\misc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {630F2610-7654-11D1-83E3-0080C71A8794} (Interconnect Resources) - https://www.ib.albb.co.uk/ebs/ie/gic.cab
O16 - DPF: GIC - https://www.ib.albb.co.uk/ebs/ie/classes.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38007.2091435185
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/20adf487f3df06885b17/netzip/RdxIE601.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cabLooking forward to your verdict...Thanks again, C.

Lorna
About the updates...
I wouldnt worry about that just now until we get cleaned up...there is a couple dialers/hijackers
to remove.
There is also a couple things we can disable from startup to help speed things up some.
You have 2 gig+ of disk space left....lots of room.
The windows updates shouldn't take much more than about 20 meg...1 gig = 1024 meg.
The listed updates for win98 also applies to 98se.
Many of the updates will help prevent some of these hijacks...without them you are pretty vulnerable.
You also want to consider installing an anti virus program.
I see you have done online scans but really not the way to go...the idea of an up to date on-board antivirus is to stop the virus in its tracks before it does anything to your system.There are a couple free ones that are low on resorces as well as taking up little space.
For now we will just deal with cleaning up what you have.
First make a folder in your downloads folder called hijack.
Hijack makes backups of what we fix so recovery is possible if something goes wrong.
Place hijackthis.exe in the hijack folder.Start hijackthis while offline and check the following to fix:
F1 - win.ini: run=C:\Program Files\AOL 7.0b\hpfsched.bat;C:\Program Files\AOL 7.0b\hpfsched.exe;C:\Program Files\AOL 7.0b\hpfsched.com;C:\Program Files\AOL 7.0b\hpfsched.scr;C:\Program Files\AOL 7.0b\hpfsched.vbs;C:\WINDOWS\hpfsched.bat;C:\WINDOWS\hpfsched.exe;C:\WINDOWS\
O2 - BHO: (no name) - {DE614603-6320-4046-A7A7-6A69CEC26F14} - C:\WINDOWS\MSLAGENT\4B_1,0,0,6_MSLAGENT.DLL <---magic control trojan
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot <---resorce hog
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\SYSTEM\MOSEARCH\BIN\MOSEARCH.exe <---resorce hog
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1034.dll,InstantAccess <---adult content dialer installed by magic control trojan
O4 - HKCU\..\Run: [mslagent] C:\WINDOWS\mslagent\MSLAGENT_.exe <---magic control trojan
O4 - Startup: Microsoft Office.lnk = C:\WINDOWS\Application Data\Microsoft\Installer\{90190409-6000-11D3-8CFE-0050048383C9}\misc.exe <---resorce hog...can be accessed through start> programs
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/20adf487f3df06885b17/netzip/RdxIE601.cab <---netster hijacker
Once those are checked close all open windows and click "fix checked"
Reboot the computer and delete the following folders if present:
C:\windows\mslagent <-folder
c:\windows\mc <-folder
c:\windows\wintrim<-folder
c:\windows\wincomp<-folder
c:\windows\winmgts<-folder
c:\windows\navpmc<-folderNext download the free Ad-aware (malware cleaner); there will be a bunch of registry items left over and possibly
other malwares Hijack does not show.http://www.lavasoftusa.com/support/download/
Update the program before running scan. (globe icon)
To set up for full scan: (run scan while offline)
http://www.lavahelp.com/howto/fullscan/index.html
When scan is done allow it to remove all found by clicking next> right click in results window> select all> next> ok at the prompt.
Once done that reboot again and post new hijack log.
__________________________________I never give up!

Well, Blender, I can't thank you enough - stupidly lost all the response just written. Here again. I think I have done all as specified. In brief (probably as well!) latest Hijack Log which you requested looks cleaner/neater:
Logfile of HijackThis v1.97.7
Scan saved at 15:59:55, on 18/03/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.exe
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\TASKMON.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\IOMEGA\DRIVEICONS\IMGICON.exe
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\CTFMON.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.exe
C:\PROGRAM FILES\PANICWARE\POP-UP SCANNER\POPUPSCN.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PROFESSIONAL\POPUPSTOPPERPROFESSIONAL.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\MY DOWNLOADS\HIJACK\HIJACKTHIS.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [MDM7] "C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.exe"
O4 - HKCU\..\Run: [Pop-Up_Scanner] "C:\PROGRAM FILES\PANICWARE\POP-UP SCANNER\POPUPSCN.exe"
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PROFESSIONAL\POPUPSTOPPERPROFESSIONAL.exe"
O4 - Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0b\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {630F2610-7654-11D1-83E3-0080C71A8794} (Interconnect Resources) - https://www.ib.albb.co.uk/ebs/ie/gic.cab
O16 - DPF: GIC - https://www.ib.albb.co.uk/ebs/ie/classes.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38007.2091435185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cabRe MS updates afraid I attempted to download some in a fit of zeal last evening before you recommended waiting.... Sori tru. PC froze and couldn't find to instal something like 7 out of 8 updates. My apologies as they may not appear (from previous exp. of similar) - let's hope they do.
Re Antivirus - had Norton and reg. updated till major crash on Fri.13thSept.02. Brother's techie recovered all (work mostly backed up) in Jan. when all other techs. failed. He didn't like Norton/gave me Sophos, which caused endless trouble. Like McAfee on Office desktop, wouldn't load AOL and constantly froze. Fine without. Techie recommended Panda, but UR so right! Happy to spend some money/as run a small charity for a developing country - have to balance budget with prudence, which clearly I have not.
My thanks in advance for next advice.

Lorna
I must say your log looks much better.
Things are running smoother?
SP1 for internet explorer 6.0 needs to be installed seperately from other udates. It still shows you just have Internet Explorer 6.0.
You will have to reboot and visit the update site a few times to get all the updates.
Hopefully now that things are clean...it should work better.I would think you had troubles installing windows updates because of the malware present taking up much of your memory needed for installing updates.
It is recommended to stop as many running programs including antivirus while installing MS updates to prevent conflicts (and freeze-ups).As for antivirus...
I do agree with your tech about Norton...
Norton is a good antivirus program but uses up tons of resorces especially if you don't have alot of ram memory in the first place...
I have a windows 98se machine with 64 megs of ram and have had troubles with norton 2002.There are 3 free ones available that I know of and all are easy on resorces and don't take up a pile of disk space. They all seem to work quite well with win98.
Anti vir personal:
http://www.free-av.com/
Avast personal:
http://www.avast.com/i_idt_153.html
AVG free:
http://www.grisoft.com/us/us_dwnl_free.php
With either Avast or AVG you will need to enter a valid email address so they can send you the activation key to install.
All have updates about once a week..sometimes more often if there is a big outbreak of new viruses.
Another small freebie spyware protection program....prevents install of spyware in the first place, does not use resorces.
Spywareblaster:
http://www.javacoolsoftware.com/spywareblaster.html
Once installed; check for and install all updates listed.
Clcik the select all button
Click the protect from selected items button.
Check for updates about once a week.
For each update you will need to click "select all" and "protect from".
You will see much less of those "do you want to install and run...whatever"
It will not block legit good active x controls.Good luck and all the best
________________________________________I never give up!

Thank you - yes, much smoother - in the message I lost, I said 'the silence is deafening!' and forgot to say so in my hastily cobbled resend....
Don't want to take up more of your time, but a couple of things just quickly --
Windows updates. You'll be pleased to know that I am now the proud possessor of IE version 6.0.2800.1106 - after a 3 hr. struggle it finally dawned on me that it's not possible to instal updates via AOL, but this was effected last night via IE itself. Little grey cells forgot to remind me this prob. occurred last August when I had to instal a javascript vulnerability update at the request of the bank we use - who, in desperation, sent me a copy themselves when I failed to secure it from MS. (I think it still appears on the list of updates needed, although I have had it for some time.)
So far so good, but this a.m. nothing else, but nothing else of the 18 o/s will instal using IE. I have registered and put the problem to MS - it's like a trip wire, whether I try large or small files - the same red message of failure.
Antivirus. Not sure if I qualify as a home user, being a not for profit charity user, so have asked Avast their opinion.
My AOL broadband pack has arrived, after which downloads are allegedly quicker, so might be best to wait till that's installed.
A question I have meant to ask. I seem to have two Temp folders in Windows - before Techie reinstated in Jan.03, Disk cleanup always got rid of Temp (as well as Temp Internet) files, and I wonder whether I can safely delete the lot?! Or just the ones calles Tmp? Current size is 141MB.
Also I now have a Windows Installation folder, which contains a lot of hefty Winzips. I sometimes delete these onece used (in AOL e.g. without ill effect). When is it safe to remove installation files?
You have kindly provided alternatives to Spybot and (it seems) some features of PopUp Stoppers - assume you would recommend I don't pay for Prof. (which didn't seem effective against the malware removed yesterday) i.e. uninstall the free trial version - what about Spybot ?
I also had something called MemoKit (from McAfee I think) which techie did't like and uninstalled last Jan., but I did notice smoother operation when I had it.
Finally, AOL Broadband provides a 'free' Firewall from McAfeee - should I download this, or will there be the same probs. as experiecned previously with their AntiVirus/is it necessary ?
Sorry to ask so many questions. Thanks a million in advance..

Lorna
Glad to hear you got most of your updates.
About the java update..shortly (i don't remember exactly when) MS will not be providing updates foe MS JVM (java)
To see what version you do have installed:
Click start
Click run
Type command
Hit entera dos window pops up
In that window at the prompt type jview.exe
Hit enterIn a few seconds a pile of text pops up and you should see at the topright
you should see "version 5.00.3810" if you have the latest installed.Since MS is no longer supporting java...you can download the newer safer sun java from here:
http://java.sun.com/j2se/1.4.2/download.html
Click the first download under the heading "Download J2SE v 1.4.2_04
If you don't plan on developing programs download the JRE version.
Installation instruction link there also.About your temp folders...if there was no modifications within the week I would say they are safe to empty out.
If any of them are in use by windows...it won't let you delete the files anyway.
Usually the temp folders just contain setup files during insall of programs, some of which do not clean up after themselves very well.
The files will go to the recycle bin...I would leave them there for a few days and if no adverse affects, then you can empty out the bin.About Spybot...I use that program regularly without problems or conflicts. I use the programs I suggested in addition to spybot for call it "layered protection" against spywares.
About popup stopper...I just use the one that comes with google toolbar, it is free and very affective taking no resorces while doing its job.
Sometimes malwares that get installed are able to bypass the popup stopper since the malware being a program on your pc is causing the popup ads...
many are not comming from web pages you are visiting but from your computer which is why some people see popups when IE is not even running.About the windows installation folder...yours is located in c:\windows ?
I have a folder in there it is called "windows update setup files" contains a ton of zips, there is also a text file in there saying the folder is safe to delete once updates are installed.
Next time you visit windows update...it will be re-created if there are any updates to install.
Check the folder there should be a text file called "this folder is safe to delete"About mcafee firewall....I don't use mcafee firewall so I cannot answer that..I use zone alarm (there is a free version) without problems.
Sygate also offers a free version, as well as I believe Kerio. I have seen good reports on all.
Since AOL is providing the firewall...I would think they would also include support if you need it.If you are using an always on connection....I definately recommend some kind of firewall or a router which acts as a hardware firewall.
Thing is with dial-up connections your IP (internet address) changes every time you connect to the net making your computer harder to find.
With broadband...you keep the same IP and because computer is online whenever it is turned on...you increase the chance for hacker attacks.About Avast...I would think since you are running a not-for-profit organisation it would be fine.
I am also not familliar with MemoKit...the only software I use from mcafee is their antivirus which i have yet not had had any problems.
Hopefully that has answered some questions.
Good luck
I never give up!

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |