![]() |
|
|||||||
| Adware & Spyware Think you may have an Adware or Spyware problem? Discuss it here. |
|
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Member
Join Date: Jun 2004
Posts: 98
|
Another spyware
I have a problem with a spyware that is using windows message service. I've tried alot of programs but nothing seems to detect it. I've tried:
Spyware doctor Ad-Aware pro Spyware search and destroy I know it's using msssrv.exe in windir\system32 please check if this is a windows file or I can delete it. How can I get rid of it? |
|
|
|
|
|
#2 |
|
Old, Cranky and Perverted
Super Moderator
Join Date: Aug 2003
Location: Watching Your every move...
Posts: 5,299
|
Well it looks like it is a McAfee file. So don't think I'd delete it. check this:
ModuleName : C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe Command Line : "C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe" ProcessID : 1472 ThreadCreationTime : 12-26-2004 11:52:36 PM BasePriority : Normal FileVersion : 1.00.1117.0 ProductVersion : 1.00.1117.0 ProductName : McAfee AntiSpyware CompanyName : Network Associates, Inc. FileDescription : McAfee AntiSpyware RealTime Service InternalName : MssSrv.exe LegalCopyright : Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : MssSrv.exe |
|
|
|
|
|
#3 |
|
Member
Join Date: Jun 2004
Posts: 98
|
why in system32 and not in it's folder?
|
|
|
|
|
|
#4 |
|
Member
Join Date: Jun 2004
Posts: 98
|
take a look at that
|
|
|
|
|
|
#5 |
|
Old, Cranky and Perverted
Super Moderator
Join Date: Aug 2003
Location: Watching Your every move...
Posts: 5,299
|
That is an advertisement.
|
|
|
|
|
|
#6 |
|
Hardware guy
Super Moderator
Join Date: Apr 2002
Location: Blasters worm farm
Posts: 3,674
|
haha don't go to that place...
Go to Control Panel> Administrative Tools> Services and disable "Messenger" Then use CCleaner and CWShredder for good measures. Also try a2 Free or ewindo Free What browser are you using ? |
|
|
|
|
|
#7 |
|
Triple Platinum Member
Join Date: Nov 2004
Location: London
Posts: 907
|
If you are getting messenger spam like that you either
a) have no firewall b) have a crap firewall c) haven't turned your firewall on You can turn off the messenger service but a proper firewall wouldn't pass those packets anyway. |
|
|
|
|
|
#8 |
|
Member
Join Date: Jun 2004
Posts: 98
|
It's probably because I allowed almost everything to connect to the Internet but the main qustion is why I can't find it with all the anti-spam program?
and I have mcafee personal firewall. |
|
|
|
|
|
#9 | |
|
Junior Member
Join Date: Oct 2004
Posts: 17
|
This is what Microsoft says about it:
Quote:
purpose BUT the @$$%#!!s of the world have figured out how to abuse it and make it popup advertisement spam in your face. The solution Microsoft presents will work. However, I recommend either disabling or completely removing the service. To Disable Windows Messenger Service (instructions) To Delete Windows Messenger Service (ShootTheMessenger Program you can download) Microsoft Knowledgebase Article 330904 (the quote is from this source)
__________________
Download links for Slimbrowser: Lite Edition of Slimbrowser | Regular Edition of Slimbrowser Relationships are ours to make; we define them, day by day, by who we choose to love and how we choose to love them. And, by these choices, define ourselves. Richard N. Patterson |
|
|
|
|
|
|
#10 |
|
Security Intelligence
TZ Veteran
Join Date: Jul 2002
Location: Software Paradise
Posts: 4,210
|
I use the ShootTheMessengerProgram on all my comps and new installs too, only in my work domain computer cant disable service, but I configure firewall to block
__________________
![]() --- 0wN3D by 3gG --- |
|
|
|
|
|
#11 |
|
Triple Platinum Member
Join Date: Nov 2004
Location: London
Posts: 907
|
Make a registry patch you know exactly what is happening that way.
________________________________________________________________ Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger] "Type"=dword:00000020 "Start"=dword:00000004 ________________________________________________________________ Not that I don't trust Steve Gibson, but I do wonder why he didn't just make a registry patch instead of a program - what was the point? Still say you should sort your firewall out though because there are exploits which can get through the same hole if you dont. |
|
|
|
|
|
#12 |
|
Hardware guy
Super Moderator
Join Date: Apr 2002
Location: Blasters worm farm
Posts: 3,674
|
Moved this thread for our brand new Spyware section
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|