Re: pop ups from messenger services

From: Bruce Chambers (bchambers_at_nospamcableone.net)
Date: 06/05/04


Date: Fri, 4 Jun 2004 19:43:55 -0600

Greetings --

    This type of spam has become quite common over the past year or
so, and unintentionally serves as a valid security "alert." It
demonstrates that you haven't been taking sufficient precautions while
connected to the Internet. Your data probably hasn't been compromised
by these specific advertisements, but if you're open to this exploit,
you most definitely open to other threats, such as the Blaster,
Welchia, and Sasser Worms that still haunt the Internet. Install and
use a decent, properly configured firewall. (Merely disabling the
messenger service, as some people recommend, only hides the symptom,
and does little or nothing to truly secure your machine.) And
ignoring or just "putting up with" the security gap represented by
these messages is particularly foolish.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-us;168893

Messenger Service Window That Contains an Internet Advertisement
Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

    If you're using AOL, you'll either need to find a 3rd party
firewall that is compatible with AOL, or switch to a real ISP that is
compatible with the real Internet. This is because AOL is an on-line
content provider that ignores international Internetworking standards
in favor of its own proprietary products, and has deliberately made
its connection software incompatible with both WinXP's built-in
firewall and WinXP's Internet Connection Sharing feature. AOL's
proprietary connection applet is deliberately designed to preclude
your setting/adjusting any of its properties, to include
enabling/disabling WinXP's ICF and ICS.

    Whichever firewall you decide upon, be sure to ensure UDP ports
135, 137, and 138 and TCP ports 135, 139, and 445 are _all_ blocked.
You may also disable Inbound NetBIOS (NetBIOS over TCP/IP). You'll
have to follow the instructions from firewall's manufacturer for the
specific steps.

    You can test your firewall at:

Symantec Security Check
http://security.symantec.com/ssc/vr_main.asp?langid=ie&venid=sym&plfid=23&pkj=GPVHGBYNCJEIMXQKCDT

Security Scan - Sygate Online Services
http://www.sygatetech.com/

    Oh, and be especially wary of people who advise you to do nothing
more than disable the messenger service. Disabling the messenger
service, by itself, is a "head in the sand" approach to computer
security. The real problem is _not_ the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert. The true problem is the unsecured computer, and
you've been advised to merely turn off the warnings. How is this
helpful?

    2) For regular Internet pop-ups, you might try the free 12Ghosts
Popup-killer from http://12ghosts.com/ghosts/popup.htm, Pop-Up Stopper
from http://www.panicware.com/, or the free Google Toolbar from
http://toolbar.google.com/, which is what I use.

    3) To deal with pop-ups caused by any sort of "adware" and/or
"spyware,"such as Gator, Comet Cursors, Xupiter, Bonzai Buddy, or
KaZaA, and their remnants, that you've deliberately (but without
understanding the consequences) installed, two products that are
quite effective (at finding and removing this type of scumware) are
Ad-Aware from www.lavasoft.de and SpyBot Search & Destroy from
www.safer-networking.org/. Both have free versions. It's even
possible to use SpyBot Search & Destroy to "immunize" your system
against most future intrusions. I use both and generally perform
manual scans every week or so to clean out cookies, etc.

Bruce Chambers

-- 
Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html
You can have peace. Or you can have freedom. Don't ever count on
having both at once. - RAH
"nvokie" <risnhi@junct.com> wrote in message
news:44AD4323-539C-423D-B5A3-083B7EA15ED6@microsoft.com...
> For several months now I have been receiving gray colored pop up
messages that read Messenger Services at the top and then they feature
an advertisement for porn sites, fixit sites for the popups, college
offers etc.
>
> What is causing this and how can I stop it.  It is getting worse
every day.  I can do nothing without these popups being right in t he
middle of my work when I am on the computer.  It is very frustrating.
Thank you in advance for your help.
>


Relevant Pages

  • Re: Windows XP home sp2 wireless network
    ... Also I have recently been having a big problem with pop-ups. ... Messenger Service pop-up can't contain a clickable link. ... unintentionally serves as a valid security alert. ... haven't been taking sufficient precautions while connected to the Internet. ...
    (microsoft.public.windowsxp.network_web)
  • Re: messenger service spam or internet pop ups
    ... recently swept cross the Internet. ... "putting up with" the security gap represented by these messages is ... Messenger Service Window That Contains an Internet Advertisement ... Internet Connection Sharing feature. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Possible Virus??
    ... and Sasser Worms that still haunt the Internet. ... ignoring or just "putting up with" the security gap represented by ... Messenger Service of Windows ... firewall and WinXP's Internet Connection Sharing feature. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Advertisements pouring in through IE
    ... You are reporting a problem with pop-up advertisements. ... Messenger Service pop-up can't contain a clickable link. ... unintentionally serves as a valid security alert. ... haven't been taking sufficient precautions while connected to the Internet. ...
    (microsoft.public.security)
  • Re: Adware and spyware
    ... >and websites on the screen that I have not asked for. ... Messenger Service pop-up can't contain a clickable link. ... unintentionally serves as a valid security alert. ... haven't been taking sufficient precautions while connected to the Internet. ...
    (microsoft.public.security)