ALERT: New MSN virus running amok

Payload filename
photoalbum.zip

Malware type

Trojan horse

Malware name
Variant of Backdoor.Win32.IRCBot.aaq (according to CISRT)

Infection vector
MSN live messenger (Other versions of MSN i m not sure)

How it looks like


NOTE: Some others have different kinds of messages, but they contain persuasive texts tempting you to open the file. There are some which does not have any message, only the file is on the conversation windows.

How it works
Once you download the file from a infected PC, the ZIP file will automatically install itself into your system without any clicking on your part, based on my observation.

What should you do
-Cease all activities.
-Exit MSN to stop the infection from spreading to others.
-Update your anti-virus, anti-spyware program
-Scan your system

Solution (Updated!)

I tested the solution found in the CISRT web page, it worked for me. So it should work for those infected.
Before you start, please make sure you have scanned your PC with a Anti-virus or Anti-spyware program.

WARNING: THE BELOW STEPS REQUIRE YOU TO USE REGEDIT. MESSING AROUND WITH THE REGISTRY WILL RENDER YOUR SYSTEM UNBOOTABLE!
SEEK PROFESSIONAL HELP IF YOU ARE NOT FAMILIAR WITH REGEDIT!

Step 1)
-Go run
-type regedit in the run box
-Find: “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad”
-Find these registry entries
: “rdfhost”
: “rdihost”
: “rdshost”

NOTE: According to my observation, only one of the 3 entries will be present
:Find the entries/filename without the quotes

Step 2)
-Run the search function
-Depending on which one of the 3 entries you found, search for the file that you found in the registry
: “rdfhost.dll”
: “rdihost.dll”
: “rdshost.dll”

Note: Find the entries/filename without the quotes


Disclaimer

-Use this guide at your own risk
-I will not be responsible for loss of data, hardware malfunction, corruption of files
-Seek professional help if you are not confident in removing the malware

Credit

-Special thanks to fellow geeks in Hardware zone and VR-zone in helping me hunt for the solutions
-Special thanks to Chinese Internet Security Response Team (CISRT) for coming out with a removal solution

-This article is dedicated to Yun Ru, a real-life bacteria warrior =D
-Special thanks to Khairu for pointing out that some info wasn’t enough

About the Author

st1ckm@n

St1ckm@n a.k.a Joe is a certified tech geek who lives on a sunny island called Singapore. He love all things tech and spends his free time either tinkering with his PC or roaming Sim Lim Square. He is also an avid gamer with an appetite for FPS or RTS games.

One Response to “ ALERT: New MSN virus running amok ”

  1. Hi! I can’t find any rdhost.rdihost or rdshost file in my SHellServiceObjectDelayLoad. Isit due to i delelte the file on my desktop? Pls advise :)

Leave a Reply

You can use these XHTML tags: <a href="" title=""> <abbr title=""> <acronym title=""> <blockquote cite=""> <code> <em> <strong>