WARNING: Trojan being sent through MSN Messenger

Reply

Join Date: Feb 2005
Posts: 1,181
Reputation: hollystyles will become famous soon enough hollystyles will become famous soon enough 
Solved Threads: 67
hollystyles's Avatar
hollystyles hollystyles is offline Offline
Veteran Poster

WARNING: Trojan being sent through MSN Messenger

 
0
  #1
Jan 24th, 2008
If one of your contacts pops up in MSN Messenger with the message:

<friend> says: Hey, isn’t this YOU?? :S http://mainmsn.com/images/viewimage.php?=your@email.com

Don't click it !!

It's a trojan, you'll think your downloading a picture, but if you try to view it, it will unpack it's payload.

If I'm too late here's how I got rid of it:

In Task Manager:

Stop the process wkssvc.exe (google for this don't just take my word for it)

Disable the startup entry for it in msconfig (Start -> Run -> type 'msconfig' without quotes and press enter)

Delete the file %SystemRoot%/System32/wkssvc.dll (You may need to reboot first, or use something like procexplorer to kill any handles too it as the file will probably be in use preventing you deleting it initially)

Your AV should pick this up if it's up to date, some people have reported their AV stopping this trojan. Mine didn't !!! Bah! Luckily I smelt a Rat straight away.
==========================================
Yadda yadda yadda...
Web junky, fevered monkey
Reply With Quote Quick reply to this message  
Join Date: Jan 2008
Posts: 1
Reputation: corbezier is an unknown quantity at this point 
Solved Threads: 0
corbezier corbezier is offline Offline
Newbie Poster

Re: WARNING: Trojan being sent through MSN Messenger

 
1
  #2
Jan 24th, 2008
I just thought I would add that personally I would NOT remove the system32/wkssvc.dll as this is a legitimate library used for the workstation service!

I followed this help and realised that the machine was unable to log on to a domain.

More info here: (I did borrow from this page - thanks for getting me started Holly and the guys at Sophos helped with the rest)

http://www.escapestudios.com/forum/showthread.php?t=873

Cheers

Ben
Reply With Quote Quick reply to this message  
Join Date: Feb 2005
Posts: 1,181
Reputation: hollystyles will become famous soon enough hollystyles will become famous soon enough 
Solved Threads: 67
hollystyles's Avatar
hollystyles hollystyles is offline Offline
Veteran Poster

Re: WARNING: Trojan being sent through MSN Messenger

 
0
  #3
Jan 25th, 2008
Corbezier,

Thanks for the clarification and link.

Yes wkssvc.dll is important that runs inside one of the svchost processes. Its the wkssvc.EXE that's the culprit.

Anyone who does delete wkssvc.dll can restore it from the recycle bin. But Windows 2000 and XP have the ICS service that monitors changes/deletions of key system files and should resurrect wkssvc.dll for you, it certainly did in my case.
Last edited by hollystyles; Jan 25th, 2008 at 3:56 am.
==========================================
Yadda yadda yadda...
Web junky, fevered monkey
Reply With Quote Quick reply to this message  
Join Date: Dec 2005
Posts: 3,306
Reputation: The Dude will become famous soon enough The Dude will become famous soon enough 
Solved Threads: 26
The Dude's Avatar
The Dude The Dude is offline Offline
Nearly a Senior Poster

Re: WARNING: Trojan being sent through MSN Messenger

 
0
  #4
Jan 25th, 2008
I think they took care of this,i get a 404 error when i goto the link..... (Good to see it dealt with so quickly)
Reply With Quote Quick reply to this message  
Join Date: Apr 2005
Posts: 16,329
Reputation: jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold 
Solved Threads: 555
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: WARNING: Trojan being sent through MSN Messenger

 
0
  #5
Jan 31st, 2008
what version of msn do you have?

live 8?
http://cdn.battlefieldheroes.com/signatures/229198472/1Player profile at BattlefieldHeroes.com, Free Shooter Game
Reply With Quote Quick reply to this message  
Join Date: Feb 2005
Posts: 1,181
Reputation: hollystyles will become famous soon enough hollystyles will become famous soon enough 
Solved Threads: 67
hollystyles's Avatar
hollystyles hollystyles is offline Offline
Veteran Poster

Re: WARNING: Trojan being sent through MSN Messenger

 
0
  #6
Feb 1st, 2008
I have Windows Live Messenger Version 8.1
==========================================
Yadda yadda yadda...
Web junky, fevered monkey
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the IT Professionals' Lounge Forum


Views: 4676 | Replies: 5
Thread Tools Search this Thread



Tag cloud for IT Professionals' Lounge
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2010 DaniWeb® LLC