CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Messenger Service Spam - Collections

 
Post new topic   Reply to topic       All -> FavForums -> Privacy [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Nov 29, 2002 2:25 pm    Post subject: Messenger Service Spam - Collections
Reply with quote

Ok, because of my first experience here:

CastleCops Link/modules.php?name=News&file=article&sid=1823

With this highly instrusive advertisement, and borrowing from spamarchive.org's idea, I'd like to give it a shot on archiving messenger service SPAM.

For now, if you have any snapshots stored, please send them to me via the link:

CastleCops Link/modules.php?name=NSN_Uploads

Or directly email them to me:

paul@computercops.biz

I'll have a section up on this soon. Please feel free to advertise this to help make the DB grow.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Johnny-B-Goode

Captain
Captain
Premium Member

Joined: Mar 30, 2002
Posts: 659
Location: Ethiopia
Premium

PostPosted: Fri Nov 29, 2002 2:48 pm    Post subject:
Reply with quote

That's a form of spam I haven't seen; I don't use messenger services much - the accounts I have go through Trillian (except the excellent Sonork client)- maybe that makes a difference?

Gordon

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Nov 29, 2002 2:53 pm    Post subject:
Reply with quote

Actually, its not related to the Messenger IM Program, but to the Messenger Service that is installed on Windows OS.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Johnny-B-Goode

Captain
Captain
Premium Member

Joined: Mar 30, 2002
Posts: 659
Location: Ethiopia
Premium

PostPosted: Fri Nov 29, 2002 2:56 pm    Post subject:
Reply with quote

Oops- Embarassed total misunderstaning on my part Wink Laughing

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Nov 29, 2002 3:10 pm    Post subject:
Reply with quote

Its a good thing to in a way... So that means you haven't gotten any. And hopefully we can train others to disable that kind of access too.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
sixonetonoffun

Private
Private


Joined: Jun 04, 2002
Posts: 43
Location: USA

PostPosted: Fri Nov 29, 2002 3:52 pm    Post subject:
Reply with quote

I posted a question about disabling windows messenger a while ago after my first run with these. What I didn't mention was how hard it was to track the real source. I don't have a snort rule that flags it. I didn't find it in Sygate Logs and I had Packet Level logging enabled. It coulda been there but I was unable to pick it out even though I at the time looked immediately. I've long since disabled the service. But I don't like this breed of advertising and I think there should be a list of companies who use it so we can boycott their products and services. Maybe even track down parent companies and let them know how we feel about this kind of advertising.

Welcome to the new millenium heh?

~Peter

Back to top
View users profile Send private message Visit posters website
StephenE

Guest
IP: 66.66.*.*






PostPosted: Sun Jan 05, 2003 8:38 pm    Post subject:
Reply with quote

Click Start->Setings -> Control Panel->Administrative Tools->Services
Scroll down and highlight "Messenger"
Right-click the highlighted line and choose Properties.
Click the STOP button.
Select Disable or Manual in the Startup Type scroll bar
Click OK

Back to top
IP: 66.176.*.*

Guest






PostPosted: Wed Jan 15, 2003 5:56 pm    Post subject:
Reply with quote

Rather than disable the service, is there no way to log these events? It's amazing MS provides now way to do this.

Back to top
IP: 68.32.*.*

Guest






PostPosted: Sat Jan 25, 2003 2:55 am    Post subject:
Reply with quote

There is actually a way to take out messenger in WIndows.

- locate the file "sysoc.inf" and edit it in NOTEPAD.
- locate the line that says:

msmsgs=msgrocm.dll,OcEntry,msmsgs.inf,hide,7

turn it to

msmsgs=msgrocm.dll,OcEntry,msmsgs.inf,,7

- now reboot your system.
- go to CONTROL PANELS - ADD REMOVE PROG. - you should see Messenger there. Now take it off.

Back to top
IP: 68.32.*.*

Guest






PostPosted: Sat Jan 25, 2003 3:04 am    Post subject:
Reply with quote

Actually I forgot to mention that you can find the ADD/REMOVE WIndows MEssenger under ADD/REMOVE WINDOWS COMPONENTS section.

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Privacy All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer