windows file protection?

B

Bob Hansen

Hi Group,
I'm getting a small dialogue box titled "windows file protection." It pops
up about every half hour telling me that it has detected spyware on my
system and asks me if I would like to remove it and learn how to protect
myself. I know this is a ploy and just close it. I run Spybot, adaware, CWS
shredder, and scan with Norton. None of these is able to find it. Any ideas
on how to get rid of this would be appreciated.
Bob
 
R

Richard Urban

You,re not using a firewall, are you?

--
Regards:

Richard Urban

aka Crusty (-: Old B@stard :)
 
S

Steve Nielsen

Bob said:
Hi Group,
I'm getting a small dialogue box titled "windows file protection." It pops
up about every half hour telling me that it has detected spyware on my
system and asks me if I would like to remove it and learn how to protect
myself. I know this is a ploy and just close it. I run Spybot, adaware, CWS
shredder, and scan with Norton. None of these is able to find it. Any ideas
on how to get rid of this would be appreciated.
Bob

Messenger service spam. Get a firewall. Also SpywareGaurd seems to block
some of them.

Steve
 
B

Bob Hansen

Yes, I have the Windows firewall enabled.


Richard Urban said:
You,re not using a firewall, are you?

--
Regards:

Richard Urban

aka Crusty (-: Old B@stard :)
 
B

Bruce Chambers

Greetings --

It's a scam, plain and simple. It's from a very unscrupulous
"business." They're trying to sell you patches that Microsoft
provides free-of-charge, and using a very intrusive means of
advertising. It's also demonstrating that your PC is very unsecure.

This type of spam has become quite common over the past year or
so, and unintentionally serves as a valid security "alert." It
demonstrates that you haven't been taking sufficient precautions while
connected to the Internet. Your data probably hasn't been compromised
by these specific advertisements, but if you're open to this exploit,
you most definitely open to other threats, such as the Blaster,
Welchia, and Sasser Worms that still haunt the Internet. Install and
use a decent, properly configured firewall. (Merely disabling the
messenger service, as some people recommend, only hides the symptom,
and does little or nothing to truly secure your machine.) And
ignoring or just "putting up with" the security gap represented by
these messages is particularly foolish.

Messenger Service of Windows
http://support.microsoft.com/default.aspx?scid=KB;en-us;168893

Messenger Service Window That Contains an Internet Advertisement
Appears
http://support.microsoft.com/?id=330904

Stopping Advertisements with Messenger Service Titles
http://www.microsoft.com/windowsxp/pro/using/howto/communicate/stopspam.asp

Blocking Ads, Parasites, and Hijackers with a Hosts File
http://www.mvps.org/winhelp2002/hosts.htm

Whichever firewall you decide upon, be sure to ensure UDP ports 135,
137, and 138 and TCP ports 135, 139, and 445 are _all_ blocked. You
may also disable Inbound NetBIOS over TCP/IP). You'll have
to follow the instructions from firewall's manufacturer for the
specific steps.

You can test your firewall at:

Symantec Security Check
http://security.symantec.com/ssc/vr_main.asp?langid=ie&venid=sym&plfid=23&pkj=GPVHGBYNCJEIMXQKCDT

Security Scan - Sygate Online Services
http://www.sygatetech.com/

Oh, and be especially wary of people who advise you to do nothing
more than disable the messenger service. Disabling the messenger
service, by itself, is a "head in the sand" approach to computer
security. The real problem is _not_ the messenger service pop-ups;
they're actually providing a useful, if annoying, service by acting as
a security alert. The true problem is the unsecured computer, and
you've been advised to merely turn off the warnings. How is this
helpful?


Bruce Chambers
--
Help us help you:



You can have peace. Or you can have freedom. Don't ever count on
having both at once. - RAH
 
A

Alex Nichol

Bob said:
Yes, I have the Windows firewall enabled.

If this is Pre-SP1 it may still be letting through items on the NETBIOS
ports, which are used by these messages, and more seriously by things
like the Blast and Sasser worms. So you may need to take steps in its
settings to block those ports explicitly - make sure everything in 130
through 140 and 440 through 450 are blocked (I misremember the exact
numbers, but there is nothing there you want open)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top