943,832 Members | Top Members by Rank

Ad:
Jan 24th, 2008
0

WARNING: Trojan being sent through MSN Messenger

Expand Post »
If one of your contacts pops up in MSN Messenger with the message:

<friend> says: Hey, isn’t this YOU?? :S http://mainmsn.com/images/viewimage.php?=your@email.com

Don't click it !!

It's a trojan, you'll think your downloading a picture, but if you try to view it, it will unpack it's payload.

If I'm too late here's how I got rid of it:

In Task Manager:

Stop the process wkssvc.exe (google for this don't just take my word for it)

Disable the startup entry for it in msconfig (Start -> Run -> type 'msconfig' without quotes and press enter)

Delete the file %SystemRoot%/System32/wkssvc.dll (You may need to reboot first, or use something like procexplorer to kill any handles too it as the file will probably be in use preventing you deleting it initially)

Your AV should pick this up if it's up to date, some people have reported their AV stopping this trojan. Mine didn't !!! Bah! Luckily I smelt a Rat straight away.
Similar Threads
Reputation Points: 262
Solved Threads: 68
Veteran Poster
hollystyles is offline Offline
1,181 posts
since Feb 2005
Jan 24th, 2008
1

Re: WARNING: Trojan being sent through MSN Messenger

I just thought I would add that personally I would NOT remove the system32/wkssvc.dll as this is a legitimate library used for the workstation service!

I followed this help and realised that the machine was unable to log on to a domain.

More info here: (I did borrow from this page - thanks for getting me started Holly and the guys at Sophos helped with the rest)

http://www.escapestudios.com/forum/showthread.php?t=873

Cheers

Ben
Reputation Points: 16
Solved Threads: 0
Newbie Poster
corbezier is offline Offline
1 posts
since Jan 2008
Jan 25th, 2008
0

Re: WARNING: Trojan being sent through MSN Messenger

Corbezier,

Thanks for the clarification and link.

Yes wkssvc.dll is important that runs inside one of the svchost processes. Its the wkssvc.EXE that's the culprit.

Anyone who does delete wkssvc.dll can restore it from the recycle bin. But Windows 2000 and XP have the ICS service that monitors changes/deletions of key system files and should resurrect wkssvc.dll for you, it certainly did in my case.
Last edited by hollystyles; Jan 25th, 2008 at 4:56 am.
Reputation Points: 262
Solved Threads: 68
Veteran Poster
hollystyles is offline Offline
1,181 posts
since Feb 2005
Jan 25th, 2008
0

Re: WARNING: Trojan being sent through MSN Messenger

I think they took care of this,i get a 404 error when i goto the link..... (Good to see it dealt with so quickly)
Reputation Points: 1054
Solved Threads: 28
Nearly a Senior Poster
The Dude is offline Offline
3,425 posts
since Dec 2005
Jan 31st, 2008
0

Re: WARNING: Trojan being sent through MSN Messenger

what version of msn do you have?

live 8?
Moderator
Featured Poster
Reputation Points: 1764
Solved Threads: 574
Moderator
jbennet is online now Online
16,510 posts
since Apr 2005
Feb 1st, 2008
0

Re: WARNING: Trojan being sent through MSN Messenger

I have Windows Live Messenger Version 8.1
Reputation Points: 262
Solved Threads: 68
Veteran Poster
hollystyles is offline Offline
1,181 posts
since Feb 2005

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in IT Professionals' Lounge Forum Timeline: Linux partition question
Next Thread in IT Professionals' Lounge Forum Timeline: Login Problem





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC