| | |
WARNING: Trojan being sent through MSN Messenger
![]() |
If one of your contacts pops up in MSN Messenger with the message:
Don't click it !!
It's a trojan, you'll think your downloading a picture, but if you try to view it, it will unpack it's payload.
If I'm too late here's how I got rid of it:
In Task Manager:
Stop the process wkssvc.exe (google for this don't just take my word for it)
Disable the startup entry for it in msconfig (Start -> Run -> type 'msconfig' without quotes and press enter)
Delete the file %SystemRoot%/System32/wkssvc.dll (You may need to reboot first, or use something like procexplorer to kill any handles too it as the file will probably be in use preventing you deleting it initially)
Your AV should pick this up if it's up to date, some people have reported their AV stopping this trojan. Mine didn't !!! Bah! Luckily I smelt a Rat straight away.
<friend> says: Hey, isn’t this YOU?? :S http://mainmsn.com/images/viewimage.php?=your@email.com
Don't click it !!
It's a trojan, you'll think your downloading a picture, but if you try to view it, it will unpack it's payload.
If I'm too late here's how I got rid of it:
In Task Manager:
Stop the process wkssvc.exe (google for this don't just take my word for it)
Disable the startup entry for it in msconfig (Start -> Run -> type 'msconfig' without quotes and press enter)
Delete the file %SystemRoot%/System32/wkssvc.dll (You may need to reboot first, or use something like procexplorer to kill any handles too it as the file will probably be in use preventing you deleting it initially)
Your AV should pick this up if it's up to date, some people have reported their AV stopping this trojan. Mine didn't !!! Bah! Luckily I smelt a Rat straight away.
•
•
Join Date: Jan 2008
Posts: 1
Reputation:
Solved Threads: 0
I just thought I would add that personally I would NOT remove the system32/wkssvc.dll as this is a legitimate library used for the workstation service!
I followed this help and realised that the machine was unable to log on to a domain.
More info here: (I did borrow from this page - thanks for getting me started Holly and the guys at Sophos helped with the rest)
http://www.escapestudios.com/forum/showthread.php?t=873
Cheers
Ben
I followed this help and realised that the machine was unable to log on to a domain.
More info here: (I did borrow from this page - thanks for getting me started Holly and the guys at Sophos helped with the rest)
http://www.escapestudios.com/forum/showthread.php?t=873
Cheers
Ben
Corbezier,
Thanks for the clarification and link.
Yes wkssvc.dll is important that runs inside one of the svchost processes. Its the wkssvc.EXE that's the culprit.
Anyone who does delete wkssvc.dll can restore it from the recycle bin. But Windows 2000 and XP have the ICS service that monitors changes/deletions of key system files and should resurrect wkssvc.dll for you, it certainly did in my case.
Thanks for the clarification and link.
Yes wkssvc.dll is important that runs inside one of the svchost processes. Its the wkssvc.EXE that's the culprit.
Anyone who does delete wkssvc.dll can restore it from the recycle bin. But Windows 2000 and XP have the ICS service that monitors changes/deletions of key system files and should resurrect wkssvc.dll for you, it certainly did in my case.
Last edited by hollystyles; Jan 25th, 2008 at 3:56 am.
what version of msn do you have?
live 8?
live 8?
http://cdn.battlefieldheroes.com/signatures/229198472/1Player profile at BattlefieldHeroes.com, Free Shooter Game
![]() |
Similar Threads
- Infected: Trojan-downloader.win32.small.dam, Spyware (Viruses, Spyware and other Nasties)
- Trojan.Cachecachekit (Viruses, Spyware and other Nasties)
- hclean.exe trojan, norton anitvirus not working and google search problems (Viruses, Spyware and other Nasties)
- i have this on my XP desktop:TROJAN-SPY.HTML.SMITFRAUD.c (Viruses, Spyware and other Nasties)
- "Your Windows is corrupted with spyware virus" Popup (Viruses, Spyware and other Nasties)
- Help i have got the coldfusion virus! (Viruses, Spyware and other Nasties)
- Trojan det and cleaned on start up/elitebar (Viruses, Spyware and other Nasties)
- remedy needed for trojan 213.159.117.130 (Viruses, Spyware and other Nasties)
- Windows XP "Hangs" in shut-down (Viruses, Spyware and other Nasties)
Other Threads in the IT Professionals' Lounge Forum
- Previous Thread: Linux partition question
- Next Thread: Login Problem
Views: 4676 | Replies: 5
| Thread Tools | Search this Thread |
Tag cloud for IT Professionals' Lounge
advice answers budget buy career carrier css degrees education game gaming gpu infodelivery infotech interview kindle microsystems multiple-os networking news pc php program projects questions r&d saas schools security simple sms spoof ssl sun tabletpc touch-screen touchscreen training vbulletin videoinprint vulnerability webdesign windows






