How Can i Stop POP UP Messages, Please Help

G

Guest

dear All,

i have in my network 25 users, all of them have winxp-SP1.

i have 5 users only they are always calling me and want to stop the POP UP
messages that appear in front of them.

i installed 3rd Party Software to stop the POP Up Messages, But its Not
working at all. and the same POP messages still appears .

is there any way to disable it , or prevent it.

Please Help
 
Y

Yves Leclerc

If Pop-Ups still happen after you block them, then you have programs that
were installed on the hard drive without your (or your users) knowledge.
This is known as spywares and you will need to clean-out each infested PC
manually (for now).

Use:

Ad Aware SE 1.05
Spybot: Search and Destroy 1.3
CWShredder
PestPatrol
Webroot Spy Sweeper


Also not that Service Pack 2 now blocks Pop-Ups and has increased security.
 
G

Gilles RONSIN

le ven. 18 said:
dear All,

i have in my network 25 users, all of them have winxp-SP1.

i have 5 users only they are always calling me and want to stop
the POP UP messages that appear in front of them.

i installed 3rd Party Software to stop the POP Up Messages, But
its Not working at all. and the same POP messages still appears .

is there any way to disable it , or prevent it.

Please Help

Hello. What kind of popup messages ? from messenger services ? so
active the firewall. from IE popup ? use another anti popup tool.
I rather keep the messenger service active because it's a good way to
be warn of a firewall disfunction.
 
G

Guest

do you use this inter office messenger? visit
http://www.grc.com/stm/shootthemessenger.htm it will turn it off.. inter
office windows messenger is a big sorce of spam.. this is not a cure for any
security issues!! but will limit popups the home page is www.grc.com
"gibson research corp" also has a port probe to see if you have any open
ports than can allow spam virus trojans etc;
 
S

Sam

Apparently, _Medo_in_Egypt_, on 02/18/2005 03:37 PM,typed:
dear All,

i have in my network 25 users, all of them have winxp-SP1.

i have 5 users only they are always calling me and want to stop the POP UP
messages that appear in front of them.

i installed 3rd Party Software to stop the POP Up Messages, But its Not
working at all. and the same POP messages still appears .

is there any way to disable it , or prevent it.

Please Help

As far I have experienced, there are two main reasons for popups:

1) your Windows messenger service running on the PCs that get pop-ups.
Disable it and the relevant pop-ups will go away. See
http://www.stopmessengerspam.com/ and click on the OS link on the right
hand side of the page.

2) Pop-ups due to the web browser (Internet Explorer). Here you are at
the mercy of the IE. I would recommend using Firefox instead
(http://getfirefox.com). This blocks up web based popups quite
satisfactorily in addition to give you tabbed browsing, much much less
chances of phising attackes, zooming in/out of font size, etc. It has
the blocker built in. IIRC, IE needs third party tools to make it stop
the popups.

These two methods were quite helpful to me, YMMV. BTW, it would be a
good idea to run Ad-aware and Spybot Search and Destroy scans and an
antivirus scan on those computers.

GL,
Sam.
 
G

Guest

I agree with Yves. An abnormal amount of popups are the result of spyware. At
this point, no browser is safe. Even Firefox is no solution, just ask the
people I work with.

Kenlori's suggestion on stopping the messenger service is also true.
Stopping the messenger service prevents some of this. The key is to get the
spyware out of the machines which, sometimes involve using the programs
listed in Safe Mode. It took me 4 months of fighting with it but I was able
to get the problem under control on 50 desktops and 50 laptops. You should
have the problem under control in a month and you'll know what works and what
doesn't.

Also as mentioned, you may want to test SP2 on one test machine. We were not
able to implement SP2 in that office although SP2 works find in my current
location. Some machines have problems with the upgrade to SP2. Machines that
come with SP2 do not seem to have these problems.

God Luck.
 
B

Bruce Chambers

Medo_in_Egypt said:
dear All,

i have in my network 25 users, all of them have winxp-SP1.

i have 5 users only they are always calling me and want to stop the POP UP
messages that appear in front of them.

i installed 3rd Party Software to stop the POP Up Messages, But its Not
working at all. and the same POP messages still appears .

is there any way to disable it , or prevent it.

Please Help


What specific kind of pop-ups are you seeing? There are at least
three varieties of pop-ups, and the solutions vary accordingly.

1) Does the title bar of these pop-ups read "Messenger Service?"

This type of spam has become quite common over the couple of
years, and unintentionally serves as a valid security "alert." It
demonstrates that you haven't been taking sufficient precautions while
connected to the Internet. Your data probably hasn't been compromised
by these specific advertisements, but if you're open to this exploit,
you may well be open to other threats, such as the Blaster Worm that
swept across the Internet last year and the currently active Sasser
Worm. Install and use a decent, properly configured firewall.
(Merely disabling the messenger service, as some people recommend,
only hides the symptom, and does little or nothing to truly secure
your machine.) And ignoring or just "putting up with" the security
gap represented by these messages is particularly foolish.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-us;168893

Messenger Service Window That Contains an Internet Advertisement
Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

Oh, and be especially wary of people who advise you to do nothing
more than disable the messenger service. Disabling the messenger
service, by itself, is a "head in the sand" approach to computer
security. The real problem is not the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert. The true problem is the unsecured computer, and
you've been advised to merely turn off the warnings. How is this
helpful?

2) For regular Internet pop-ups, you might try the free 12Ghosts
Popup-killer from http://12ghosts.com/ghosts/popup.htm, Pop-Up Stopper
from http://www.panicware.com/, or the Google Toolbar from
http://toolbar.google.com/. Alternatively, you can upgrade your WinXP
to SP2, to install IE's pop-up blocker. Another alternative would be
to use another browser, such as Mozilla or Firefox, which has pop-up
blocking capabilities. (But I'd avoid Netscape; it carries too much
extraneous AOL garbage.)

3) To deal with pop-ups caused by any sort of "adware" and/or
"spyware,"such as Gator, Comet Cursors, Xupiter, Bonzai Buddy, or
KaZaA, and their remnants, that you've deliberately (but without
understanding the consequences) installed, two products that are
quite effective (at finding and removing this type of scumware) are
Ad-Aware from www.lavasoft.de and SpyBot Search & Destroy from
www.safer-networking.org/. Both have free versions. It's even
possible to use SpyBot Search & Destroy to "immunize" your system
against most future intrusions. I use both and generally perform
manual scans every week or so to clean out cookies, etc.

Additionally, manual removal instructions for the most common
varieties of scumware are available here:

PC Hell Spyware and Adware Removal Help
http://www.pchell.com/support/spyware.shtml

More information and assistance is available at these sites:

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

The Parasite Fight
http://www.aumha.org/a/parasite.htm

--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 
B

Bruce Chambers

kenlori said:
do you use this inter office messenger? visit
http://www.grc.com/stm/shootthemessenger.htm it will turn it off.. inter
office windows messenger is a big sorce of spam.. this is not a cure for any
security issues!! but will limit popups the home page is www.grc.com
"gibson research corp" also has a port probe to see if you have any open
ports than can allow spam virus trojans etc;


I realize that you're trying to help, and that such an intent is
commendable, but please don't post potentially harmful advice.

Merely disabling the messenger service, as Gibson's band-aid "Shoot
the Messenger" applet, is a dangerous "head in the sand" approach to
computer security that leaves the PC vulnerable to threats such as the
W32.Blaster.Worm.

The real problem is _not_ the messenger service pop-ups; they're
actually, if unintentionally, providing a useful service by acting as a
security alert. The true problem is the unsecured computer, and your
only advice, however well-intended, was to turn off the warnings.

Equivalent Scenario: You over-exert your shoulder at work or
play, causing bursitis. After weeks of annoying and sometimes
excruciating pain whenever you try to reach over your head, you go to
a doctor and say, while demonstrating the motion, "Doc, it hurts when
I do this." The doctor, being as helpful as you've been, replies,
"Well, don't do that."

The only true way to secure the PC, short of disconnecting it from
the Internet, is to install and *properly* configure a firewall; just
installing one and letting it's default settings handle things is no
good. Unfortunately, this does require one to learn a little bit more
about using a computer than used to be necessary.


--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 
B

Bruce Chambers

Sam said:
1) your Windows messenger service running on the PCs that get pop-ups.
Disable it and the relevant pop-ups will go away. See
http://www.stopmessengerspam.com/ and click on the OS link on the right
hand side of the page.


I realize that you're trying to help, and that such an intent is
commendable, but please don't post potentially harmful advice.

Merely disabling the messenger service, as the web site you pointed
the OP to recommends, is a dangerous "head in the sand" approach to
computer security that leaves the PC vulnerable to threats such as the
W32.Blaster.Worm.

The real problem is _not_ the messenger service pop-ups; they're
actually providing a useful service by acting as a security alert. The
true problem is the unsecured computer, and your only advice, however
well-intended, was to turn off the warnings. Was this truly helpful?

Equivalent Scenario: You over-exert your shoulder at work or
play, causing bursitis. After weeks of annoying and sometimes
excruciating pain whenever you try to reach over your head, you go to
a doctor and say, while demonstrating the motion, "Doc, it hurts when
I do this." The doctor, being as helpful as you've been, replies,
"Well, don't do that."

The only true way to secure the PC, short of disconnecting it from
the Internet, is to install and *properly* configure a firewall; just
installing one and letting it's default settings handle things is no
good. Unfortunately, this does require one to learn a little bit more
about using a computer than used to be necessary.



--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 
S

Sam

Apparently, _Bruce Chambers_, on 02/18/2005 07:21 PM,typed:
I realize that you're trying to help, and that such an intent is
commendable, but please don't post potentially harmful advice.

Merely disabling the messenger service, as the web site you pointed
the OP to recommends, is a dangerous "head in the sand" approach to
computer security that leaves the PC vulnerable to threats such as the
W32.Blaster.Worm.

The real problem is _not_ the messenger service pop-ups; they're
actually providing a useful service by acting as a security alert. The
true problem is the unsecured computer, and your only advice, however
well-intended, was to turn off the warnings. Was this truly helpful?

Equivalent Scenario: You over-exert your shoulder at work or
play, causing bursitis. After weeks of annoying and sometimes
excruciating pain whenever you try to reach over your head, you go to
a doctor and say, while demonstrating the motion, "Doc, it hurts when
I do this." The doctor, being as helpful as you've been, replies,
"Well, don't do that."

The only true way to secure the PC, short of disconnecting it from
the Internet, is to install and *properly* configure a firewall; just
installing one and letting it's default settings handle things is no
good. Unfortunately, this does require one to learn a little bit more
about using a computer than used to be necessary.


Quite interesting. To the OP: no one can overstress the importance of a
good nice solid firewall. If you already do not have one, then seriosly
consider getting one.

However, I am not sure (maybe because I lack technical details how
Windows Messenger is supposed to work internally) I am comfortable by
still allowing the messenger pop-ups. My main concern is: do the pop-up
boxes actually allow any arbitrary code to be executed if I click
anywhere on them or on any button on them?

If No, i.e. if I do get pop-ups and clicking on them does not or can do
any harm whatsover, then you are right, they can be considered as
indications of lack of a good firewall. However, if Yes, then I wouldn't
want them, good firewall or no.

Moreover, can I send the popups from my computer to myself? In other
words, can a spyware produce messenger service pop-ups?

Thanks for the interesting point of view though,
Sam.
 
J

Jim Byrd

Hi Medo - There are currently two classes of things going on that are
causing people popup difficulties. If you get popups even when your browser
is not connected to the Internet with a title bar reading "Messenger
Service", then these are most likely due to open NetBios TCP ports 135, 139
and 445 and UDP ports 135, 137-138 and a UDP port in the range of
1026-1029.. You really need to block these with a firewall as a general
protection measure. You can stop the popups by turning off Messenger
Service; however, this still leaves you vulnerable. If you have an NT-based
OS such as XP or Win2k, you should probably also specifically block TCP
593, 4444 and UDP 69, 139, 445, and install the very important 824146 patch
from MS03-039, here: http://support.microsoft.com/default.aspx?kbid=824146
to block the Blaster worm as well as several other parasites.


See: Messenger Service Window That Contains an Internet Advertisement
Appears http://support.microsoft.com/?id=330904 which identifies reasons to
keep this service and steps to take if you do.

You can test your system and follow the 'Prevention' link to get additional
information here:
http://www.mynetwatchman.com/winpopuptester.asp Unless you have very good
reasons to keep this active, it should be turned off in Win2k and XP. Go
here and do what it says:
http://www.itc.virginia.edu/desktop/docs/messagepopup/ or, even better, get
MessageSubtract, free, here, which will give you flexible control of the
service and viewing of these messages:
http://www.intermute.com/messagesubtract/help.html Recommended.

(FWIW, ZoneAlarm's default Internet Zone firewall configuration blocks the
necessary ports to prevent this use of Messenger Service. I don't know the
situation with regard to other firewalls.)

Messenger Service is not per se Spyware or something that MS did wrong - It
provides a messaging capability which is useful for local intranets and is
also sometimes (albeit nowdays infrequently) used by some applications to
provide popup messages to users. However, it can also be (and now frequently
is) used to introduce spam via this open NetBios channel. For a single user
home computer, it normally isn't needed and can be turned off which will
eliminate the spam popups. This DOESN'T, however, remove the vulnerability
of having these ports open, when in fact they aren't needed, since they can
be perverted in other ways as well, some of which can be much more damaging
than just a spam popup.



If you're getting a lot of popups while surfing, then the following may be
useful:

#########IMPORTANT#########
Before you try to remove spyware using any of the programs below, download
both a copy of LSPFIX here:

http://www.cexx.org/lspfix.htm

AND a copy of Winsockfix for W95, W98, and ME
http://www.tacktech.com/pub/winsockfix/WinsockFix.zip
Directions here: http://www.tacktech.com/display.cfm?ttid=257

or here for Win2k/XP http://files.webattack.com/localdl834/WinsockxpFix.exe
Info here: http://www.spychecker.com/program/winsockxpfix.html
Directions here: http://www.iup.edu/house/resnet/winfix.shtm

The process of removing certain malware may kill your internet connection.
If this should occur, these programs, LSPFIX and WINSOCKFIX, will enable you
to regain your connection.

NOTE: It is reported that in XP SP2, the Run command netsh winsock reset
will fix this problem without the need for these programs. (You can also
try this if you're on XP SP1. There has also been one, as yet unconfirmed,
report that this also works there.) Also, one MS technician suggested the
following sequence:

netsh int reset all
ipconfig /flushdns

See also: http://windowsxp.mvps.org/winsock.htm for additional XPSP2
info/approaches using the netsh command.
#########IMPORTANT#########



#########IMPORTANT#########
Show hidden files and run all of the following removal tools from Safe mode
or a "Clean Boot" when possible. Reboot and test if the malware is fixed
after using each tool.

HOW TO Enable Hidden Files
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339

Clean Boot - General Win2k/XP procedure, but see below for links for other
OS's (This for Win2k w/msconfig - you can obtain msconfig for Win2k here:
http://www.3feetunder.com/files/win2K_msconfig_setup.exe ):

1. StartRun enter msconfig.

2. On the General tab, click Selective Startup, and then clear the 'Process
System.ini File', 'Process Win.ini File', and 'Load Startup Items' check
boxes. Leave the 'boot.ini' boxes however they are currently set.

3. In the Services tab, check the "Hide All Microsoft Services" checkbox,
and then click the "Disable All" button. If you use a third party firewall
then re-check (enable) it. For example, if you use Zone Alarm, re-check the
True Vector Internet Monitor service (and you may also want to re-check
(enable) the zlclient on the Startup tab.) Equivalent services exist for
other third party firewalls. An alternative to this for XP users is to
enable at this time the XP native firewall (Internet Connection Firewall -
ICF). Be sure to turn it back off when you re-enable your non-MS services
and Startup tab programs and restore your normal msconfig configuration
after cleaning your machine.

4. Click OK and then reboot.

For additional information about how to clean boot your operating system,
click the following article numbers to view the articles in the Microsoft
Knowledge Base:
310353 How to Perform a Clean Boot in Windows XP
http://support.microsoft.com/kb/310353
281770 How to Perform Clean-Boot Troubleshooting for Windows 2000
http://support.microsoft.com/kb/281770/EN-US/
267288 How to Perform a Clean Boot in Windows Millennium Edition
http://support.microsoft.com/kb/267288/EN-US/
192926 How to Perform Clean-Boot Troubleshooting for Windows 98
http://support.microsoft.com/kb/192926/EN-US/
243039 How to Perform a Clean Boot in Windows 95
http://support.microsoft.com/kb/243039/EN-US/
#########IMPORTANT#########




Sometimes the tools below will find files which they are unable to delete
because they are in use. A program called Copylock, here,
http://noeld.com/programs.asp?cat=misc#CopyLock can aid in the process of
"replacing, moving, renaming or deleting one or many files which are
currently in use (e.g. system files like comctl32.dll, or virus/trojan
files.)" Another is Killbox, here:
http://www.downloads.subratam.org/KillBox.zip
A third which is a bit different but often useful is Delete Invalid File,
here: http://www.purgeie.com/delinv.htm which handles invalid/UNC
file/folder name deleting, rather than the in use problem



Download and run Stinger.exe, here:
http://download.nai.com/products/mcafee-avert/stinger.exe or from the link
on this page: http://vil.nai.com/vil/stinger/ ME/XP users be sure to read:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm


Download sysclean.com , from Trend Micro, here:
http://www.trendmicro.com/download/dcs.asp along with the latest pattern
file, here: http://www.trendmicro.com/download/pattern.asp Be sure to read
the "How-to" info here:
http://www.trendmicro.com/ftp/products/tsc/readme.txt (You might also want
to get Art's updater, SYS-UP.Zip, here for future updating of these:
http://home.epix.net/~artnpeg/). (If you download and use the updater from
the beginning, it will automatically handle downloading the other files.)
Place them in a dedicated folder after appropriate unzipping. Show hidden
and system files (HowTo here:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339)
Disable Restore if you're on XP or ME (directions here:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm), then boot to
Safe mode (HowTo here:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406)
Read tscreadme.txt carefully, then do a complete scan of your system
in Safe mode and clean or delete anything it finds. Reboot to normal mode
and re-run the scan again.

This scan may take a long time, as Sysclean is VERY extensive and thorough.
For example, one user reported that Sysclean found 69 hits that an
immediately prior Norton AV v. 11.0.2.4 run had missed.



Popups - The best way to start is to get Ad-Aware SE Personal Edition, here:
http://www.lavasoftusa.com/support/download/. UPDATE, set it up in
accordance with this: http://forum.aumha.org/viewtopic.php?t=5877 and run
this regularly to get rid of most "spyware/hijackware" on your machine. If
it has to fix things, be sure to re-boot and rerun AdAware again and repeat
this cycle until you get a clean scan. The reason is that it may have to
remove things which are currently "in use" before it can then clean up
others. configure Ad-aware for a customized scan, and let it remove any bad
files found.....

Then, courtesy of NonSuch at Lockergnome, open Ad-aware then click the gear
wheel at the top and check these options to configure Ad-aware for a
customized scan:

General> activate these: "Automatically save log-file" and "Automatically
quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes",
"Scan registry", "Deep scan registry," "Scan my IE Favorites for banned
sites," and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during
scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister
objects prior to deletion" and "Let Windows remove files in use after
reboot."

Click "Proceed" to save your settings, then click "Start." Make sure
"Activate in-depth scan" is ticked green, then scan your system. When the
scan is finished, the screen will tell you if anything has been found, click
"Next." The bad files will be listed. Right click the pane and click "Select
all objects" - This will put a check mark in the box at the side, click
"Next" again and click "OK" at the prompt "# objects will be removed.
Continue?"

Courtesy of http://www.nondisputandum.com/html/anti_spyware.html: HINT: If
Ad Aware is automatically shut-down by a malicious software, first run
AWCloak.exe, http://www.lavasoftnews.com/downloads/AAWCloak.exe, before
opening Ad Aware. When AAWCloak is open, click “Activate Cloakâ€. Than open
Ad Aware and scan your system.



Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. Update before starting, then after fixing ONLY RED
things with SpyBot S&D, be sure to re-boot and rerun SpyBot again and repeat
this cycle until you get a clean "no red" scan. The reason is that SpyBot
sometimes has to remove things which are currently "in use" before it can
then clean up others.

Then, there are a variety of third party "Popup Killers" available. I
normally use AdShield, which, if you maintain its Block List every now and
then, almost totally stops this. In addition, it stops a variety of
ads/banners/etc. (particularly spyware like doubleclick) on pages I access.
This is probably all you'll need; however, I've also investigated a program
called webwasher which appears to be very good, but decided that AdShield
was sufficient. At the bottom of this post, you'll find a list provided
courtesy of bc_acadia of a number of free popup blockers with links.

****** NOTE: As of 28 Apr 03 AdShield appears to have partnered with a new
reseller, and AdShield is no longer free. There is a trial version of
AdShield3; however, IMO it is seriously crippled in not being able to import
or export block lists and I think for reasonable utility one would have to
go to the full version. While I don't normally recommend non-free software,
I personally will continue to use AdShield3, since I think it is the best
currently available combined Popup/Ad/Malware blocker, but you should be
aware of the fact that it now costs, ($29.95), whereas the earlier versions
upon which I based my original recommendation were free, although not nearly
as capable as the AdShield3 release. I've included below links to both the
older free version and the new paid version. You'll have to investigate and
make your own choice in the matter. *******

Here are a number of AdShield-related links:

http://www.fsd1.org/technology/Files/AdShield.exe - AdShield1.2 (free)
http://www.internettechs.net/utilities/AdShield.exe - AdShield1.2 (free)
http://ftp.ural.ru/home/index/windows/networking/utils/AdShield -
AdShield1.2 (free)
http://www.megalog.ru/info/utilz/AdShield.zip - AdShield1.2 (free)
http://www.allstarss.com/store/adshield.html - AdShield3
http://www.ad-shield.com/ AdShield3 Info/Purchase/Block List
http://www.mvps.org/winhelp2002/block.txt - (Mike Burgess' .txt Block List
for AdShield - Recommended)
http://www.mvps.org/winhelp2002/block.zip - Mike Burgess' Zipped Block List
for AdShield - Recommended)

http://www.songwave.com/software/adshield_blocklist.txt (40,000 pornsites
blocked - *VERY* large list - use at your own risk)
http://www.chrismyden.com/temp/block.abl (chrismyden's blocklist in .abl
format - Recommended)
http://www.staff.uiuc.edu/~ehowes/resource.htm#AdShield (Eric Howes AGNIS
for AdShield block list - Recommended) (BTW, Eric's site contains a wealth
of very valuable information about all aspects of net security - Very Highly
Recommended)


Here's a good AdShield test site, courtesy of siljaline: "Make ***SURE***
you have your block scripted popups enabled
http://www.mediaboy.net/1010100-1100001-1111010/gahk/>>>> [Warning this URL
opens a multitude of Browser windows almost instantly - YOU'VE BEEN
WARNED!]"

http://www.webwasher.com - Webwasher


For WinXP users, Service Pack 2 has a built-in popup stopper which at first
look appears to be fairly effective.


Additionally, some people have recommended Popup Stopper and PopupBuster,
but they have also been reported or experienced to cause perceived problems
for some people with "normal" links in IE6 such as Google search results and
links from OE. Some proponents of PopupBuster assert, however, that this is
normal operation for this program under certain circumstances which can be
overridden if necessary. YMMV Another "Proxy" type blocker similar to
Webwasher and Proxomitron but supposedly a bit easier to configure is
Privoxy here: http://www.privoxy.org/

Also, the free Google Tool Bar has a builtin popup blocker which is fairly
effective.


A very clever alternative approach to general ad (vice Popup) blocking is
outlined here:
http://www.sherylcanter.com/articles/oreilly_20040330_HostsPac.php
and here: http://s91363763.onlinehome.us/BlackHoleProxy/index.html
The approach is similar to that used in eDexter, but improved. I've tried
it, and it does work as advertised. (<groan> - sorry 'bout that!) :)
Probably should only be considered by more knowlegable users, as it's a
little complicated to set up using the directions given if you don't already
know a bit. (It also has some tendency to block some things you'd rather it
didn't at times if PAC files are used instead of the HOSTS file due to its
use of regular expressions for blocking definitions without some tuning.)


There is additonal information about setting up and using AdShield, and
about using the Restriced Zone (and an additional list) here:
http://www.mvps.org/winhelp2002/hosts.htm

Lastly, ZoneAlarmPro3/4 has added provisions for stopping adds/popups,
handling cookies, web bugs, and scripting/ActiveX components in addition to
it's firewall functionality. Not free, but I have used it with my other
AdBlocking stuff (AdShield, etc.) turned off as a test, and it appears to be
very good indeed. So far I've experienced no problems at all with it set in
its High Security modes for Ads although others have reported the need to
temporarily turn it off to reach some sites. Also, Agnitum's Outpost
Firewall supports a plug-in for this: "Pre-configured to block most banner
advertisement. Can be configured manually or by simply dragging and dropping
unwanted banners into the Ad Trashcan." I have no experience as to how
effective it is, but I have received a favorable report.

There's good information about hijacking in general and fixes available for
specific hijackers here: http://spywareinfo.com/articles/hijacked/
http://gmpservicesinc.com/Articles/hijack.asp
http://www.mvps.org/inetexplorer/Darnit.htm#pop_up
http://www.doxdesk.com/parasite/

bc_acadia's list:

"Some popup blockers. All of these are 100% pure freeware, no trial
periods. Some of these do more than just handle popups.

Pow!: http://www.analogx.com/contents/download/network/pow.htm
NoAds: http://www.southbaypc.com/NoAds/
PopupEraser: http://www.webknacks.com/popuperaser.htm
Stop-the-Pop: http://www.bysoft.se/sureshot/stopthepop/index.html
Internet Organizer: http://www.sf.yucom.be/wdprojects/
PopKi: http://ranfo.com/popki.html
PopUpKiller: http://sourceforge.net/projects/puk/
AdCruncher Proxy:
http://mysite.verizon.net/~mr_fish/AdCruncher/ReadMe.html
KillAd: http://www.iomagic.org/fsc/
ClickOff: http://www.johanneshuebner.com/en/download.html
PopupBuster: http://www.popupbuster.com/PopUpBuster/
Free Surfer: http://www.kolumbus.fi/eero.muhonen/FS/
Window Shades: http://www.g-m-m.com/Software/WindowShades/index.php
AdShield (my personal favorite): http://www.ad-shield.com/
PopupStopper: http://www.panicware.com/popupstopper.html
Proxomitron (Is no longer supported and has a learning curve):
http://www.proxomitron.org/
For those who don't want third party stuff, your own pc's built-in
host file:
http://www.mvps.org/winhelp2002/hosts.htm and
http://www.accs-net.com/hosts/


Here is a review of 61 popup killers, not all of them are free:
http://www.popup-killer-review.com/index.htm"

NOTE that this site also contains a good, comprehensive series of popup
killer tests. Some good additional tests are also available here:
http://www.webknacks.com/aptest.htm


There's another popup test page here:
http://www.kephyr.com/popupkillertest/index.html


Another good test page and lists of both free and cost popup blockers is
here: http://www.popuptest.com/ Recommended

An excellent test site here: http://www.popupcheck.com/ Highly
Recommended.

Another list of some popup blockers:
http://www.messaging-software.net/popup-killer-software.htm

If you install and keep UPDATED a good HOSTS file, it can help you avoid
most adware/malware. See here: <http://www.mvps.org/winhelp2002/hosts.htm>
(Be sure it's named/renamed HOSTS - all caps, no extension)



You might want to consider installing Eric Howes' IESpyAds, SpywareBlaster
and SpywareGuard here to help prevent this kind of thing from happening in
the future:

IESpyads - https://netfiles.uiuc.edu/ehowes/www/resource.htm "IE-SPYAD adds
a long list of sites and domains associated with known advertisers,
marketers, and crapware pushers to the Restricted sites zone of Internet
Explorer. Once you merge this list of sites and domains into the Registry,
the web sites for these companies will not be able to use cookies, ActiveX
controls, Java applets, or scripting to compromise your privacy or your PC
while you surf the Net. Nor will they be able to use your browser to push
unwanted pop-ups, cookies, or auto-installing programs on your PC." Read
carefully. Tutorials here:
http://www.bleepingcomputer.com/forums/tutorial53.html

http://www.javacoolsoftware.com/spywareblaster.html (Prevents malware Active
X installs, blocks spyware/tracking cookies, and restricts the actions of
potentially dangerous sites) (BTW, SpyWareBlaster is not memory resident ...
no CPU or memory load - but keep it UPDATED) The latest version as of this
writing will prevent installation or prevent the malware from running if it
is already installed, and, additionally, it provides information about and
fixit-links for a variety of parasites. Tutorial here:
http://www.bleepingcomputer.com/forums/tutorial49.html

http://www.javacoolsoftware.com/spywareguard.html (Monitors for attempts to
install malware) Keep it UPDATED. Tutorial here:
http://www.bleepingcomputer.com/forums/tutorial50.html
All three Very Highly Recommended


â— SpywareBlaster is probably the best preventive tool currently available,
expecially if supplemented by using the Immunize function in SpyBot S&D and
a good HOSTS file (see next). IMPORTANT NOTE: A good additional source of
preventive blocking for ActiveX components is the Blocking List available
here: http://www.spywareguide.com/blockfile.php While smaller than the
SpywareBlaster list, it contains some different malware CLSIDs and appears
to be updated with new threats more frequently. Strongly Recommended as a
supplement to SpywareBlaster. Read all of the instructions in the Expert
package download carefully. You might want to consider using:
http://www.changedetection.com/monitor.html to monitor and notify you of
changes/updates to this list (or other programs, for that matter).


â— Next, install and keep updated a good HOSTS file. It can help you avoid
most adware/malware. See here: http://www.mvps.org/winhelp2002/hosts.htm (Be
sure it's named/renamed HOSTS - all caps, no extension) Additional tutorials
here: http://www.spywarewarrior.com/viewtopic.php?t=410 (overview) and here:
http://www.bleepingcomputer.com/forums/tutorial51.html (detailed)


â— Lastly, with regards to cookies: The following overview of the approach I
recommend is courtesy of Mel's Spyware Tools: XML-Menu for IE6 -
(https://netfiles.uiuc.edu/ehowes/www/main.htm, click on IE6 Tools on
website)

"This package contains a full menu of custom Import XML files that can be
used to manipulate IE6's handling of cookies in the Internet and Trusted
zones (the Privacy tab controls only the Internet zone). The files are
divided into three sets: one "short list" of recommended files, and two
"advanced" lists containing a wide range of possible Privacy configurations.
The ReadMe covers the basics of using custom XML Import files and details
all the files that are available. A .REG file that can be used to restore
the default Privacy tab settings is included."

This is the technique that I use and, while I do very infrequently have to
override on some sites that don't have a Privacy Policy in place, I've found
it almost infallible in stopping bad cookies (I use 1-e, BTW) FWIW, MVP Eric
Howes' site, above, is one of the very best on the net with regard to
anything having to do with security. Very Highly Recommended.

Perhaps these will help.

--
Please respond in the same thread.
Regards, Jim Byrd, MS-MVP



In
 
B

Bruce Chambers

Sam said:
However, I am not sure (maybe because I lack technical details how
Windows Messenger is supposed to work internally) I am comfortable by
still allowing the messenger pop-ups. My main concern is: do the pop-up
boxes actually allow any arbitrary code to be executed if I click
anywhere on them or on any button on them?


I'm not aware of any arbitrary code that can be carried by the
messenger service. Even the URLs to "spamvertised" web sites that they
often contain are non-functional.

If No, i.e. if I do get pop-ups and clicking on them does not or can do
any harm whatsover, then you are right, they can be considered as
indications of lack of a good firewall. However, if Yes, then I wouldn't
want them, good firewall or no.


A good point, and something to keep in mind for the future.

Moreover, can I send the popups from my computer to myself? In other
words, can a spyware produce messenger service pop-ups?

Yes, you (or another application on your computer) can send messages to
yourself or to other users on a network. Remember, part of the
messenger service's "raison d'etre" is to be used by enterprise
antivirus and/or backup application to notify administrators of problems.


--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 
S

Sam

Apparently, _Bruce Chambers_, on 19/02/05 11:15,typed:
I'm not aware of any arbitrary code that can be carried by the
messenger service. Even the URLs to "spamvertised" web sites that they
often contain are non-functional.


So, this doubt and .....

Yes, you (or another application on your computer) can send messages
to yourself or to other users on a network. Remember, part of the
messenger service's "raison d'etre" is to be used by enterprise
antivirus and/or backup application to notify administrators of problems.


.... this feature are two reasons I disable the service. Of course I
first make sure I have a good firewall (actually zone alarm while being
behind a router) and anti-spyware (ad-aware and spybot at least) on my
computer in addition to an anti-virus.

regards,
Sam.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top