|
-
May 7th, 2004, 10:57 AM
#1
[RESOLVED] Pop-ups
Hi, when i leave my comp on for a long time and come back to it i have a lot of pop-up messages, mostly about free smileys.
I have pop-up blocker on norton internet security and i have the google toolbar, so i dont see how they are getting through.
Can sum1 please help me please. Thanks
Ps.can sum1 please reccomend some ad removal and spyware removal programs so i can see if its some sort of spyware or something i have
-
May 7th, 2004, 11:02 AM
#2
James
Sounds like the messenger service.
download Shoot the Messenger so it can disable the messenger service.
As for spyware removal, download Spybot S&D and Ad-aware, both in my sig below.
Keep them updated and run regular scans.
To prevent spyware from entering your pc download install Spyware Blaster, also in my sig. This works in the background.
Who are you? Introduce yourself here
P3-450 powered by
Intel Core 2 Duo E6600
Gigabyte 965P DQ6
4 Gig Crucial Ballistix PC6400
Gainward Nvidia Geforce 7950GT
2X Western Digital Caviar 320GB SATA2
Soundblaster X-Fi XtremeMusic
Samsung SH-D162C DVD Rom
Lite-On SHM-165P6S DVDRW
Samsung 20" LCD Syncmaster 206BW
Thermaltake Kandalf VA9000SWA Tower
Tagan Dual Engine 700W PSU
XP PRO SP3/Windows 7 64-bit
--------------
Samsung NC10 2GB Ram
Windows 7 32-bit
-
May 7th, 2004, 11:06 AM
#3
ok, thanks
whats the messenger service?
-
May 7th, 2004, 11:11 AM
#4
Messenger servce is supposed to be used for broadcasting network messages, but spammers use this to get spam to your computer. very annoying.
Who are you? Introduce yourself here
P3-450 powered by
Intel Core 2 Duo E6600
Gigabyte 965P DQ6
4 Gig Crucial Ballistix PC6400
Gainward Nvidia Geforce 7950GT
2X Western Digital Caviar 320GB SATA2
Soundblaster X-Fi XtremeMusic
Samsung SH-D162C DVD Rom
Lite-On SHM-165P6S DVDRW
Samsung 20" LCD Syncmaster 206BW
Thermaltake Kandalf VA9000SWA Tower
Tagan Dual Engine 700W PSU
XP PRO SP3/Windows 7 64-bit
--------------
Samsung NC10 2GB Ram
Windows 7 32-bit
-
May 7th, 2004, 08:34 PM
#5
net messenger
Originally posted by P3-450
James
Sounds like the messenger service.
download Shoot the Messenger so it can disable the messenger service.
As for spyware removal, download Spybot S&D and Ad-aware, both in my sig below.
Keep them updated and run regular scans.
To prevent spyware from entering your pc download install Spyware Blaster, also in my sig. This works in the background.
net messenger allows you to network multiple computers together.
disable net messenger:
start
control panel
administrative tools
services
drill down to Msection to messenger
right click and select properties
click start up
select disable
-
May 8th, 2004, 02:22 AM
#6
Start>run, then type in services.msc, look for Messenger in the list and right click and select disable. That works too .
Last edited by Syzich; May 8th, 2004 at 02:26 AM.
-
May 10th, 2004, 01:49 PM
#7
ok, thanks but it was already disabled wen i went on it
-
May 10th, 2004, 07:05 PM
#8
new pop ups
Hi, I've all of a sudden been getting tons of Pop-ups all connected with a theme:
"Spyware detected on Your PC"...
"Your internet privacy is at risk"...
"Spyware removal"...
"OS...WINDOWS XP detected
Browser...Internet Explorer 6.0 detected
Chance of spyware on your pc...99%"
I've been getting all of these type pop-ups in the last week or so.
My recent downloads were:- upgrade of Kazaa Media Desktop
- upgrade of AOL Instant Messenger
- Microsoft Virtual Machine Java stuff
Plus, my brother may or may not have used my pc when i wasn't around. So if anyone knows what program may be causing this or what spyware that Spybot S&D hasn't detected, please let me know
These always put up when i go to any website or reload the browser, but for some reason they don't occur when i visited this site.
Chris
Thanks to all helpers!!!
-
May 10th, 2004, 07:15 PM
#9
Chris
This sounds like Messenger service.
Use the methods that have been already suggested above to stop it.
Also id suggest getting rid of Kazaa, as it is a hotbed for all sorts of spyware and virus's.
Who are you? Introduce yourself here
P3-450 powered by
Intel Core 2 Duo E6600
Gigabyte 965P DQ6
4 Gig Crucial Ballistix PC6400
Gainward Nvidia Geforce 7950GT
2X Western Digital Caviar 320GB SATA2
Soundblaster X-Fi XtremeMusic
Samsung SH-D162C DVD Rom
Lite-On SHM-165P6S DVDRW
Samsung 20" LCD Syncmaster 206BW
Thermaltake Kandalf VA9000SWA Tower
Tagan Dual Engine 700W PSU
XP PRO SP3/Windows 7 64-bit
--------------
Samsung NC10 2GB Ram
Windows 7 32-bit
-
May 10th, 2004, 07:55 PM
#10
Yup, get rid of Kazaa. It sounds like you need a good firewall as well:
Zone Alarm
Kerio Personal Firewall
Outpost
Sygate Personal Firewall
Nick.
-
May 13th, 2004, 06:58 PM
#11
I do have Norton Antivirus/Internet Security...does that include a firewall?
I ran that shoot the messenger thingie and those popups are persisting.
Also, my homepage keeps getting reset or redirected to some about:blank search enginey type page.
Last edited by czman007; May 13th, 2004 at 07:00 PM.
Thanks to all helpers!!!
-
May 13th, 2004, 07:39 PM
#12
SECURITY
Originally posted by czman007
I do have Norton Antivirus/Internet Security...does that include a firewall?
I ran that shoot the messenger thingie and those popups are persisting.
Also, my homepage keeps getting reset or redirected to some about:blank search enginey type page.
were me,i'd install AVG av and Zone Alarm,firewall. norton seems plaqued with problems. those 2 downloads are free. have yoyu ad-aware? seems you have some spyware some where.
-
May 14th, 2004, 06:01 PM
#13
I've downloaded ad-aware and ran it...still i have these popups and the homepage resets
Thanks to all helpers!!!
-
May 14th, 2004, 06:20 PM
#14
Download HijackThis and extract it to its own permanent folder, run a scan and save the log, copy and paste it into your next reply.
you can get HijackThis from my sig below.
Who are you? Introduce yourself here
P3-450 powered by
Intel Core 2 Duo E6600
Gigabyte 965P DQ6
4 Gig Crucial Ballistix PC6400
Gainward Nvidia Geforce 7950GT
2X Western Digital Caviar 320GB SATA2
Soundblaster X-Fi XtremeMusic
Samsung SH-D162C DVD Rom
Lite-On SHM-165P6S DVDRW
Samsung 20" LCD Syncmaster 206BW
Thermaltake Kandalf VA9000SWA Tower
Tagan Dual Engine 700W PSU
XP PRO SP3/Windows 7 64-bit
--------------
Samsung NC10 2GB Ram
Windows 7 32-bit
-
May 14th, 2004, 06:27 PM
#15
Logfile of HijackThis v1.97.7
Scan saved at 6:25:43 PM, on 5/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Norton Internet Security Professional\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\stardock\TrayServer.exe
D:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
D:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
D:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
D:\Program Files\CursorXP\CursorXP.exe
D:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\winlogon.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
D:\Program Files\Norton Internet Security Professional\ccPxySvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\mdm.exe
D:\Program Files\Creative\MediaSource\RemoteControl\OSDMenu.EXE
C:\Program Files\AIM95\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\m.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\m.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\m.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\m.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\m.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\m.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: PerfectNavBHO Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL
N3 - Netscape 7: # Mozilla User Preferences
user_pref("aim.session.screenname", "randomstuff93");
user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.4");
user_pref("intl.accept_languages", "");
user_pref("intl.charsetmenu.browser.cache", "ISO-8859-1");
user_pref("prefs.converted-to-utf8", true);
user_pref("signon.SignonFileName", "71183499.s");
user_pref("timebomb.first_launch_time", "1071183579515625");
user_pref("browser.helperApps.neverAsk.openFile", "application%2Fx-java-jnlp-file");
(C:\Documents and Settings\Chris\Application Data\Mozilla\Profiles\default\yj3gwpac.slt\prefs.js)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\3.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E7C7355D-49EB-4520-AE44-70FAF87B3719} - C:\WINDOWS\m.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\3.bin\MYBAR.DLL
O4 - HKLM\..\Run: [1A:Stardock TrayMonitor] "C:\Program Files\Common Files\stardock\TrayServer.exe"
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [LogonStudio] "D:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [CTSysVol] D:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] D:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] D:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKCU\..\Run: [CursorXP] D:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [RemoteCenter] d:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winlogon] c:\windows\winlogon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: PartyPoker.com (HKLM)
O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/ocx/12119/CTSUEng.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/28bd8a64761b434...p/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...035.6170601852
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/ocx/12119/CTPID.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Instal...sinstaller.cab
Thanks to all helpers!!!
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|