[956] in winnt
Re: Questionable Pop UP
daemon@ATHENA.MIT.EDU (Kerem B Limon)
Wed Oct 16 09:04:26 2002
Message-Id: <5.1.1.6.2.20021016090102.04f30a38@po11.mit.edu>
Date: Wed, 16 Oct 2002 09:03:57 -0400
To: Barbara Santorella <bsantore@mit.edu>
From: Kerem B Limon <kerem.limon@MIT.EDU>
Cc: ntpartners@mit.edu
In-Reply-To: <3DAD5BF3.79625B71@mit.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
(Jon Hunt might already have commented on this elsewhere, and I assume he
will as soon as he sees your notes.) We have run into spam distributed
using the Messenger service (the service that enables those pop-ups), and
WinAthena, for example, has already disabled this service on their
workstations unless the local admin overrides it for some reason.
From the discussion there, so far we have identified the following legit
uses of the NetBIOS Messenger service:
>We have now identified 3 types of software that use the NetBIOS Messenger
>service for legitimate purposes. These are:
>
>- some "desktop" UPS units use the Messenger service to notify users when
>there has been a power failure and the computer is using the UPS. More
>expensive UPS units do not use this service for notification. (identified by
>MIT)
>
>- some older printers send notifications about paper jams, empty paper bins,
>and low toner, via the Messenger service. Newer printers tend to use SNMP or
>other mechanism for this notification. (identified by Microsoft)
>
>- the VirusScan alter service (identified by Kerem)
If you are not dependent on any of these (and the last one is really for
sending notices to an Admin console for VirusScan, not individual
machines), I'd suggest disabling the Messenger service, as few other apps
use it anyway.
If you need details on how to do this, let us know and Jon or I could give
details.
Kerem
At 2002-10-16 08:30 Wednesday, Barbara Santorella wrote:
> Hello all,
>
> I have had a questionable pop up appear on several of my computers. A
> window pops up on the screen that appears from Windows "Messenger
> Service" it states that the message is from WEBPOPUP06 and is addressed
> to the actual computer name. It then goes on encouraging the recipient
> to call a phone number to purchase a diploma. Has anyone seen this?
>Do
> I need to be concerned from a security standpoint? I have a .jpg of
>the
> message, if anyone is inerested. I did not want to send an attachment
> to the whole list.
>
> Barbara Santorella
> Windows Administrator
> MIT Bates