Annoying Message Service popup (MS Problem)

Posted:
in Genius Bar edited January 2014
I feel weird post a PC question at a Mac message board, but I am hoping some PC buffs here can help me out.



My PC is throwing up annoying, pornographic related popup windows on the screen and I can find a way to stop them. It seems to use a program called message service which is built into Windows so I can't delete it. I ran a virus scan to see if it is a virus with no luck. I ran Ad-aware to see if it is spyware with no luck. I also ran a port scan from my G5 to my PC. It found a few open ports, but the one that got my attention was port "1025-Blackjack". I don't like the sound of that so I blocked it with my firewall. Damn spyware! However, I also ran the port scan on my other PC's and they all have port 1025 open but don't have pop-ups.



There are 2 things that can be happening. 1) The program is activating from somewhere in my computer. 2) the message is triggered from the network. Still, I can't find a suspicious program on my computer and I can't stop a trigger from entering my computer.



I am out of options.



Anyone have any ideas how to kill this thing? I'm going to have to start digging around in the registry soon and for those of you who know me, that will send shivers down your spines.



EDIT: Just wondering, is there a way/application to record the contents of internet packets using my G5?

Comments

  • Reply 2 of 7
    ast3r3xast3r3x Posts: 5,012member
    Isn't that real annoying? Worst part is that...I guess after an update, but it will come back on and you have to shut it off again
  • Reply 3 of 7
    durandaldurandal Posts: 277member
    Quote:

    Originally posted by Ebby

    I feel weird post a PC question at a Mac message board, but I am hoping some PC buffs here can help me out.



    My PC is throwing up annoying, [...] popup windows on the screen [...] ran a port scan from my G5 to my PC. It found a few open ports, but the one that got my attention was port "1025-Blackjack". I don't like the sound of that so I blocked it with my firewall. [...]




    Well, Blackjack is just the name of the service/server that's usually running on port 1025 (i.e. the service for which this port is reserved). But any other service could use this port as well, one of them being named/BIND (a DNS server application) that uses the first free port that it can find to get a response from other DNS servers (found this information here: http://cert.uni-stuttgart.de/archive.../msg00120.html ). What OS are you running on the PC?



    Quote:

    Originally posted by Ebby



    There are 2 things that can be happening. 1) The program is activating from somewhere in my computer. 2) the message is triggered from the network. Still, I can't find a suspicious program on my computer and I can't stop a trigger from entering my computer.





    Brad was right here. The messages/popups are triggered by the Windows Messaging Service which a user might switch off following the steps described on the page that Brad provided a link to.



    Quote:

    Originally posted by Ebby



    EDIT: Just wondering, is there a way/application to record the contents of internet packets using my G5?




    Well, there is a MacOS X version of the famous network analyzing tool Ethereal. You can obtain it via Fink

    http://fink.sourceforge.net/download...php?phpLang=en. But since I'm not familiar with neither Ethereal nor Fink you'll have to ask other folks for help with these, sorry.



    greetz,

    durandal
  • Reply 4 of 7
    ebbyebby Posts: 3,110member
    Hey, thanks brad. "Google is my friend" I was embarrassed and not thinking straight because it was my mom who complained about "naughty popup windows". Awkward!
  • Reply 5 of 7
    ebbyebby Posts: 3,110member
    Quote:

    Originally posted by durandal

    What OS are you running on the PC?



    I am running Windows 2000. I thought about installing XP, but never got past their EULA.
  • Reply 6 of 7
    durandaldurandal Posts: 277member
    Quote:

    Originally posted by Ebby

    I am running Windows 2000. I thought about installing XP, but never got past their EULA.



    Okay... I was just asking this question to find out whether the possibility of a DNS server using your port 1025 is real. If you're using the server variant of Win2k it is (Win2k server does include some DNS server app AFAIK) and if not... well, nevermind
  • Reply 7 of 7
    Safeboot, and then you may be able to stop it. The easiest way would be to activiate it from the System Configuration Utility (Run: msconfig), and click Safeboot:







    (Yes, I know I'm on XP and you're on 2000, but it should still work the same way)
Sign In or Register to comment.