Google Answers Logo
View Question
 
Q: How to locate a virus like executable file running as an application. ( Answered 4 out of 5 stars,   6 Comments )
Question  
Subject: How to locate a virus like executable file running as an application.
Category: Computers > Security
Asked by: chasnyc-ga
List Price: $2.00
Posted: 01 Nov 2002 09:13 PST
Expires: 01 Dec 2002 09:13 PST
Question ID: 95490
I need help locating an executable file on my machine which pops up an
advertisement for University Diplomas. It does this once per day or
session. I assume I installed something by mistake but I don't see
anything strange in my Add/Remove Programs list. Neither my anti-virus
software or Ad-aware pick it up. If I go to Windows Task Manager, I
can see it running as an application called "Messenger Service". If I
select "go to process", it shows that it's using  the "csrss.exe"
process. Is there a utility which I can use to locate the executable
files causing this? Something which maps running
applications/processes to executables? I'm on WINXP Home.
Answer  
Subject: Re: How to locate a virus like executable file running as an application.
Answered By: aceresearcher-ga on 01 Nov 2002 09:47 PST
Rated:4 out of 5 stars
 
chasnyc,

Unfortunately, this new form of scumware invades your computer through
you Windows Messenger Service. To get rid of it, you need to disable
and stop using Microsoft Messenger, at least until Microsoft and/or
the firewall software companies develop a fix for it.

"Spam Masquerades as Admin Alerts" by Brian McWilliams, Wired News
(October 15, 2002)
"A new breed of pop-up ads is appearing mysteriously on Microsoft
Windows users' computers. The so-called "Messenger spams" have
security experts and system administrators scratching their heads --
and recipients fuming... Flynn said the recent pop-ups appear to use
port 135, which is often left unprotected by a firewall because it's a
vital conduit for communicating with a Microsoft service called RPC...
Carvey and other security experts said users can protect themselves
from unwanted pop-ups by disabling the Windows Messenger service
and/or properly configuring their firewalls."
http://www.wired.com/news/technology/0,1282,55795,00.html

"Spammers crack through Windows" by Robert Lemos, Special to ZDNet
News (October 18, 2002)
"Spammers have co-opted an administration feature in Microsoft's
Windows operating systems and are using it to bring up intrusive
advertisements on Internet-connected computers."
http://zdnet.com.com/2100-1105-962483.html

Example of the offending pop-up, from the Computer Security Department
at James Madison University in Harrisonburg, VA (October 29, 2002):
Instructions for "Disabling the Messenger Service" appear about
halfway down the page, followed by "Blocking Network Access to the
Messenger Service".
http://www.jmu.edu/computing/security/info/winmsg.shtml


Search Strategy

"university diplomas" pop-up
://www.google.com/search?q=%22university+diplomas%22+pop-up&hl=en&lr=&ie=UTF-8&oe=UTF-8&start=10&sa=N


Before Rating my Answer, if you have any questions, please post a
Request for Clarification, and I will do what I can to get you what
you need.

I hope this information enables you to solve your problem!

Regards,

aceresearcher
chasnyc-ga rated this answer:4 out of 5 stars

Comments  
Subject: Re: How to locate a virus like executable file running as an application.
From: crimson_harlequin-ga on 01 Nov 2002 09:19 PST
 
Make sure you don't have "gator" installed in add/remove.
Subject: Re: How to locate a virus like executable file running as an application.
From: crimson_harlequin-ga on 01 Nov 2002 09:23 PST
 
There's a new kind of "pop-up" that's really not a pop up at all, it
uses Windows (XP included) own ability to receive network messages.

Does the university diploma message have any color or buttons or is it
text only with a bar across the top that says something like "network
message"?
Subject: Re: How to locate a virus like executable file running as an application.
From: crimson_harlequin-ga on 01 Nov 2002 09:25 PST
 
To stop pop-ups, you might try a shareware program like "pop-up
stopper pro." www.tucows.com has lots of these, if you are going to
get one from tucows, sort by your OS (WinXP) and by rating (number of
stars).
Subject: Re: How to locate a virus like executable file running as an application.
From: crimson_harlequin-ga on 01 Nov 2002 09:28 PST
 
Here's the article about the network messanging spam I mentioned in an
earlier comment: http://www.techtv.com/screensavers/answerstips/story/0,24330,3374542,00.htm
Subject: Re: How to locate a virus like executable file running as an application.
From: mister-ga on 01 Nov 2002 10:12 PST
 
Try the anti spyware at www.lavasoftusa.com
Subject: Re: How to locate a virus like executable file running as an application.
From: crimson_harlequin-ga on 01 Nov 2002 12:45 PST
 
---HOW TO TURN OFF MESSANGER SERVICE IN XP/NT/Win2k---

The easiest way, if you are running a firewall is to block port 139.
Otherwise:

1. Click on the Start button and open the control panel.
2. Open the Performance and Maintenance control panel and go to
Administrative Tools.
3. Now double-click on Services, then scroll to Messenger.
4. Double-click Messenger and click Stop to stop the service.
5. Change the startup type to Disable.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy