Constant "Messenger Service" warning popup windows

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dolphinocean, Sep 9, 2005.

  1. dolphinocean

    dolphinocean Private E-2

    Our computer was recently attacked by a nasty virus, and after seeking professional help with change of system from MS Win ME to MS Win XP Professional v 2002, the computer still runs slow and constantly receives numerous popup "Messenger Service" warning windows with various messages.

    The messages usually gave warning about our system, such as "windows has encountered an internal error" or that "the registry was being corrupted by virus infection". It then suggested that we visit certain websites, such as e-regclean.com, updatepatch.info, ms-repair.com, fixmyreg.com, etc to fix the problem.

    Should we visit those recommended websites to fix the problem as suggested? Or are they computer viral messages that may lead us to more problems?

    Please help. Our system is: MS Win XP Professional v 2002, Intel Pentium III processor 551 MHZ, 64.0 MB of RAM, free space 11.9 GB, total size 14.3 GB.

    ThanKs!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hopefully the "professional" that you went to did not upgrade from Me to XP. That would not be a good idea. It is much better to do a clean install with WinXP. While using a 550 Mhz processor is possible it will be slow. But 64 Mb of RAM is not acceptable for WinXP. You really should have at a minimum 256 Mb.

    Do you use Windows Messenger?

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang, thanks for your reply.

    After I posted my question, I made a search and found a previous post with similar problem with "Windows Messenger". I followed the directions to disable the "Windows Messenger" and the popups were gone. The next day I was able to use the computer without the popups, but the computer was still running slow. Then, the following day when my roommate attempted to turn on the computer it didn't start normally.

    There was a black screen with paragraph of words, and two directions, i.e. to press F1 for set-up, and F2 for default something and continue. We didn't know what to do, so we decided to press F2.

    Then the computer ran thru the check and came up with a screen that stated it couldn't find the printer. We then select certain choices given, and identified the printer from 2 choices given, and the computer came back to normal, but slow as usual.

    No, I don't use "Windows Messenger".

    Given that 64 Mb RAM is not acceptable, and given that I have anti-virus program such as Ad-Aware SE, Spy Sweeper, and MeAfee, would that slow down my computer even more if I download all the required tools?

    Also, I've seen the results of HijackThis posted on the web-site, my roommate was concerned about sensitive and important files being posted out in the internet.


    When I get home from the library, I'll follow your instructions and check back on this site for your reply to my questions.

    Thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No the other tools use very little or no resources. Just do not enable Spybot's Teatimer. The SDhelper can be enabled. It does not use very much. Spybot's Immunize uses no resources. SpywareBlaster uses 0 resource. You only use some resources when you scan with Spybot and that is temporary. If you have the free version of Ad-aware, it is not using any resources either until you scan.

    To help fix your system I would need to see everything in your log. It is highly unlikely that anything in your HJT log (accept maybe some IP addresses for your system) are sensitive. And even your IP address can be easily obtained by any site you connect to. We can always edit your message after the fact to delete anything that you are worried about.
     
    Last edited: Sep 12, 2005
  5. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang, I appreciate your quick response. I read thru the "READ ME FIRST BEFORE ASKING FOR SUPPORT.." and have some questions:

    On "Getting Prepared" section, #1 it stated "Disable System... if you are infected. Our computer was once infected. After seeking professional help to have the problem fixed I am not sure whether the computer is still infected or not. So do I still follow instruction #1?

    On the same section, #2 it stated "Network Security, Workstation Netlogon Services & Remote Procedure Call (RPC Helper.." Whate are they? Are they part of the XP system software? Also, the statement, "Only do this if you have the about:blan or home search hijack"> What are "about:blank" and "home search hijack". Are they virus programs? If they are how do I tell?

    Sorry for being slow on this... but thanks so much for your help.
     
  6. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang,
    I did Step 1to 3 and am trying to download tools in step 4. I tried to create a folder on C:\ drive but do not know how to start. How to nagivate to C:\ folder.

    Also, I tried to download one of the tools, it asked whether I want to open, or save, which should I choose. It also have a save to: desktop as default.

    Another question, our computer already has Lavasoft Ad-Aware SE Personal, do I still download the Ad-Aware SE?

    Thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your first message, it sounds like you have problems. Otherwise why would you be here. So yes! Disable System Restore.

    Step 2 specifically tells you what they are:
    Only do this step if you have the about:blank or home search hijack.

    So no they are not valid parts of system software. You would know if you had the hijackers because your internet surfing would be totally disrupted sending you to about:blank or other pages that make references to "Only the Best" etc. There are many forms of these hijackers. If you are not sure, just look for the EXACT three service names that are mentioned. If you do not see the EXACT names, then just continue to the next steps.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is an example on how to create a folder in the root directory ( this is c:\ ) of drive C.

    - Click START and select Explore. This brings up Windows Explorer.
    - Select the drive where Windows is installed (normally C:)
    - Now click the on the top menu where it says File and then select New.
    - Then select Folder
    - A new folder is created and highlighted.
    - Just type Spyware-Tools to overwrite the default name (New Folder)

    You should save the downloaded tools to the above folder. And then later you will go to that folder to install the programs by running them. Do not save them to the Desktop.

    Just make sure you are running the same version of Ad-Aware SE (Ad-Aware SE is Ad-Aware SE Personal) as we show in our link. Also makes sure it has the current updated reference list.
     
  9. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang,

    I had followed and completed the relevant part of "READ ME FIRST BEFORE ASKING FOR SUPPORT...". There were no "Network Security Service", "Workstation Netlogon Servie", or "RPC Helper" found. So far I have been without any trouble.

    Step 1 to 4 were completed. Not all steps were completed without problem.

    When in safe mode I was not able to connect to the internect to perforem scan at Bitdefender and RavAntivirus. I had to run them in normal mode.

    Step 4: CCleaner was installed and then manually deleted because when I ran RavAntivirus it identified CCleaner as infected. So I didn't use CCleaner. After that Ad-Aware, VX2 Cleaner, Stinger,Spybot S & D, Kill2Me, HSR reported no virus threat. CWshredder reported no "Coolwebsearch" not found in system.

    When trying to run about:Blaster I was not able to open and install it. I clicked on the "reflist.dll" icon but didn't know which program to open it with. So, I didn't use about:Blaster.

    Ad-aware SE was already in my system (desktop) and I upgraded it with VX2 Cleaner Plug-in. Spbot, SpywareBalster, and MeAfee Aver Stinger was downloaded to desktop prior to receiveing your post on how to create a new folder.

    Finally, I also uninstall my Spysweeper and McAcfee because they took too much disk space. I replaced them with Antivir.

    So far, everything seems to run smoothly. If there is anything that I need to go back and re-do, please let me know. I was new to all these and it was nerve wrecking trying to figure out every steps that didn't came up according to indtruction.

    Thanks a lot for your help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    CCleaner is not infected. Reinstall it and run it. Ignore any reports from RAVantivirus about CCleaner. They are false positives.

    You do not need to run HSremove or about:Buster (not about:blaster) unless you have an HSA or about:blank hijacker which it does not seem like you have. But why would you be clicking on reflist.dll. That is not the executable for about:Buster. AboutBuster.exe is the executable.

    I cannot tell from you message whether you are having any malware problems or not. Are you?
     
  11. dolphinocean

    dolphinocean Private E-2

    My initial problem was about constant popups "Messenger Service" windows that warned of infected or currupted system. At that time there were no problem with other malware problem after it was fixed by a professional (where he switched my OS from WinME to Win XP Pro. Although the computer was running slow, I guess that could be attributed to the small RAM size (64 MB).

    Now the "Messenger Service" popup problem is gone after I had disabled it. And when I followed the instruction "READ ME FIRST BEFORE ASKING FOR SUPPORT..." as suggested, the only infected program reported was "ccsetup123" something like that. I then quickly deleted the program.

    Now that you told me that CCleaner is not infected and to reinstall and run it, I did just that. But when I tried to run and update it, my computer began to run slower and I kept getting a message from Task Manager window that said the program was not responding and whether to report problem to MS. Again, I quickly unistall the program and did a disk cleanup and defragmentation.

    The result was that 10 files were reported not able to be defragmented. It was listed as 1 KB \Documents and Settings\Neal\ntuser.dat.LOG.

    I tried to do Win updates but were unsuccessful.

    I also found some files that I'm not sure what were they for listed as:
    ModemLog_LucentWinModem
    KB828741
    KB834707-IE65P1-20040929.091901
    KB835732
    KB842773
    Q329115

    I saved them in a floppy disk and deleted the files from my computer.

    Other than that my computer appears to run ok for now.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of the files you listed are problems. They are all valid files from Windows Updates and one is probably for you Lucent Modem. I'm not sure what your problem is with why Ccleaner will not run but it is not infected with anything.

    There are always some protected OS files that cannot be defragged.

    Your PC may not be able to get Windows Updates because you may not have a valid license. Did you purchase a valid Windows XP license and have this "professsional" install a valid Win XP copy? If not, that could be your problem. I would not have installed Win XP on such an old, slow system with such a small amount of RAM. Adding more RAM will help a little, but in my opinion anything less than 800 Mhz with XP can still be too slow.


    If you complete ALL of the steps of the READ ME and post your HJT log, I can look to see if any malware is causing you problems.
     
  13. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang,
    Last night the ccsetup.exe file was still hidden in my system despite having been unistalled. When I did the disk cleanup and defrag, the % free space was 81%. Before I reinstalled CCleaner it was at 82%.

    So I spent the whole night thru the morning trying to figure out what happened to the other 1% storage space. I deleted some files, and it still was at 81%. So I went back and re-do the steps in "READ ME FIRST BEFORE ASKING FOR SUPPORT...".

    Result: Ad-Aware found I critical object and 9 non-criticals. I did the quarantine and removal, and the % free space increased to 83 %. And now the computer runs fine.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ccsetup123.exe is the installation file for Ccleaner. It is not the actual installed program itself. Uninstalling a program, does not delete the files that you downloaded to install the program. Anything you downloaded is still wherever you downloaded it too. Also, ccsetup123.exe is only 498k in size so it is not using very much disk space. Your change in disk space that is free is probably just due to your internet cache, cookies, and Windows temp files, swap space etc. This is probably why running Ad-Aware resulted in freeing up some disk space too. The longer you are on and the more things you do, the larger the temporary space used by Windows will become.

    None of what we are discussing here is malware. So either post your HJT log so we can look to see if you have any malware issues, otherwise you should continue discussing whatever it is that you think you are having problems with in the Software Forum. I still see no problems.
     
  15. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang,
    My previous post was partially completed when my keyboard just stopped working. I checked the device and the driver in the system and it said the device was working properly. But yet when I tried to type nothing came up, not even in wordpad. So, I did a sys restore to get it work.

    Anyway, on your prior post, regarding the validity of license of the installed Win XP by the professional who fixed our computer, I really don't know. I don't know much about the technicality of computer except to point and click and type. I'm now just beginning to learn all these thru your siteand the "Howsatuffworks" in the internet.If it is not legit, can we switch back to our original WinME version? Or could we use an entirely diffent OS such as Unix?

    Regarding the disk space before deleting ccsetup.exe I did clean up all the internet files including the offline filesand deleted all cooking in the internet option. I also did a manual one by one cookie file delete (about 15 to 20 of them) in the system folder which I found in C:. Even after that the Ad-ware identified the 1 critical object as some kind of tracking cookie.

    I know my CP is old but I didn't know any better when I sought professional help to fix the viral problems. I already spent too money to have it fixed and it was running ok at that time except for the constant "messenger service" windows popups that was bothering me. I've lost my job since June and I'm not able to spent any more money for upgrade of RAM especially with recent cash donation to Katrina disaster relief from my raining day fund.

    I think now that the problem of "messenger service" window popups is gone, and the computer is running fairly good speed, I'm not going to risk it for any more trouble to attempt the HJT log.

    I wish some people would go after those virus and malware creating criminals. They are nothin good but the scum of the earth.

    I thank you and this great site for all your help!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running HijackThis does not cause any problems as long as you do not select any items and try to Fix them on your own. All it does is display a list of running processes and a whole variety of registry keys. What you do afterwards with that information is where the tricky part begins.

    Yes you can always go back to your original WinMe system (assuming you have the CD and the ability to reinstall all the necessary software and drivers). I would bet that your XP copy is not legal. If you were given a CD with a license key on it for WinXP then maybe it is valid. Otherwise it is probably not.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds