Subscribe: Subscribe to BigBlueBallRSSSubscribe to BigBlueBall by emailEmailSubscribe to BigBlueBallTwitter


Go Back   BigBlueBall Forums > Instant Messaging > Windows Live Messenger Support
Forgot Password? Register
Connect with Facebook

Reply
 
LinkBack (8) Topic Tools
  8 links from elsewhere to this Post. Click to view. #1 (permalink)  
Old 03-30-2007, 05:22 PM
Junior Member
 

Join Date: Nov 2006
Posts: 3
warriors292 is on a distinguished road (10)
photo album.zip

my daughter has been sent this through msn and has stupidly opened it, the trouble is it is now sending itself to all her contacts trying to get them to open it, when this happens her computer freezes and wont do anything for a min. after looking it up it seems to be a virus of some kind but avg hasn`t picked up on it, i have deleted the folder ic c: program files called photo album.zip but it is still sending itself onto all her contacts...
anyone help ????
Reply With Quote
 

 
  #2 (permalink)  
Old 03-31-2007, 02:11 AM
Philip's Avatar
WLM Guy
 

Join Date: Jun 2006
Location: Penang, Malaysia
Posts: 1,691
Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)
Send a message via MSN to Philip Send a message via Yahoo to Philip
Quote:
Originally Posted by warriors292 View Post
my daughter has been sent this through msn and has stupidly opened it, the trouble is it is now sending itself to all her contacts trying to get them to open it, when this happens her computer freezes and wont do anything for a min. after looking it up it seems to be a virus of some kind but avg hasn`t picked up on it, i have deleted the folder ic c: program files called photo album.zip but it is still sending itself onto all her contacts...
anyone help ????
Hi there, and welcome to the BBB forums. I did some searching, it seems that the photo album.zip file contains the W32/IrcWorm-A. The only antivirus vendor who had some info on it was Sophos. The easiest way to get rid of this worm would be to download a trial copy of Sophos Antivirus here. Make sure to also update it after installation. Before installing Sophos, uninstall any existing antivirus programs in your system.

Please post back if you're still encountering problems.
Reply With Quote
  #3 (permalink)  
Old 03-31-2007, 08:29 PM
Junior Member
 

Join Date: Mar 2007
Posts: 3
X Blader is on a distinguished road (10)
i have this thing in to i did try your suggestion but it failed to do anything for me please can you give any more information on how i can get this of my wlm please


never mind it seams to be out now

well i signed into my messenger this morning and about 30 mins into the convo it started doing it again the pif fil is removed and eveything alone with it and also the virus scan removed it but it is still in please help

regards

Last edited by X Blader; 04-01-2007 at 02:37 PM. Reason: Its back
Reply With Quote
  #4 (permalink)  
Old 03-31-2007, 09:32 PM
Philip's Avatar
WLM Guy
 

Join Date: Jun 2006
Location: Penang, Malaysia
Posts: 1,691
Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)
Send a message via MSN to Philip Send a message via Yahoo to Philip
Quote:
Originally Posted by X Blader View Post
i have this thing in to i did try your suggestion but it failed to do anything for me please can you give any more information on how i can get this of my wlm please


never mind it seams to be out now

regards
Some additional info: this appears to be a new worm spreading on the net, that's why none of the antivirus vendors (except Sophos) has posted anything about it. The moral of the story is: don't open any files sent from your contacts, unless you've verified it with them. And keep your antivirus program up to date.
Reply With Quote
  #5 (permalink)  
Old 04-01-2007, 02:41 PM
Junior Member
 

Join Date: Mar 2007
Posts: 3
X Blader is on a distinguished road (10)
well i signed into my messenger this morning and about 30 mins into the convo it started doing it again the pif fil is removed and eveything alone with it and also the virus scan removed it but it is still in please help

well its gone again this time i did nothing with it ill update if it show up tomorrow

regards

Last edited by X Blader; 04-01-2007 at 04:31 PM. Reason: its gone again
Reply With Quote
  #6 (permalink)  
Old 04-01-2007, 10:37 PM
Philip's Avatar
WLM Guy
 

Join Date: Jun 2006
Location: Penang, Malaysia
Posts: 1,691
Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)
Send a message via MSN to Philip Send a message via Yahoo to Philip
Quote:
Originally Posted by X Blader View Post
well i signed into my messenger this morning and about 30 mins into the convo it started doing it again the pif fil is removed and eveything alone with it and also the virus scan removed it but it is still in please help

well its gone again this time i did nothing with it ill update if it show up tomorrow

regards
Today (April 2) I searched the major antivirus vendor's websites, and unfortunately, there's still not much about this W32/IrcWorm-A. If your system is still infected, you can try the following. Warning: this involves editing the Registry. Be very careful when doing this, because editing the wrong keys could cause your system to malfunction. Do this at your own risk.
  • Go to My Received Files in My Documents folder. Delete (Shift + Delete) the Photo Album.zip folder and its contents.
  • Go to C:\Windows. Delete the Photo Album.zip folder.
  • In C:\Windows\System, find the rdfhost.dll or rdshost.dll files. Delete them.
  • Go to Start > Run. Type regedit to open the Registry. Navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
    ShellServiceObjectDelayLoad rdshost {5344BB88-3DE1-409F-8307-C85923A1F4DD} Delete this key (right-click and click on Delete)
  • Navigate to HKCR\CLSID\{5344BB88-3DE1-409F-8307-C85923A1F4DD} Delete this key.
  • Reboot your computer.
Check to see whether the problem still exists. Please post back to let me know.

Last edited by Philip; 04-08-2007 at 10:06 AM.
Reply With Quote
  #7 (permalink)  
Old 04-03-2007, 06:25 PM
Junior Member
 

Join Date: Mar 2007
Posts: 3
X Blader is on a distinguished road (10)
well is all gone now so im relieved its all gone no come backs

thanks for the help
Reply With Quote
  #8 (permalink)  
Old 04-08-2007, 08:57 AM
Junior Member
 

Join Date: Apr 2007
Posts: 3
frankie7 is on a distinguished road (10)
I cannot find this directory at all. On my system it just does'nt appear. Not the way you say it anyway.

I cannot get rid of this at all.

I keep getting loads of chat boxes opening up all the time, and my contacts say i keep asking them do they ant to see my photoalbum.zip how this got onto my system, i have no idea.

Is there any other way to fix this ?

Last edited by frankie7; 04-08-2007 at 09:05 AM.
Reply With Quote
  #9 (permalink)  
Old 04-08-2007, 09:07 AM
Philip's Avatar
WLM Guy
 

Join Date: Jun 2006
Location: Penang, Malaysia
Posts: 1,691
Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)Philip has much to be proud of (1000)
Send a message via MSN to Philip Send a message via Yahoo to Philip
Quote:
Originally Posted by frankie7 View Post
I cannot find this directory at all. On my system it just does'nt appear. Not the way you say it anyway.

I cannot get rid of this at all.
Hi Frankie,

Welcome to BBB. Which directory couldn't you find? What operating system are you using? Did you follow the steps in post #2 below, and still unsuccessful?

Did a Google search for the worm, but it seems like Sophos is the only antivirus vendor posting info about it.
Reply With Quote
  #10 (permalink)  
Old 04-08-2007, 09:14 AM
Junior Member
 

Join Date: Apr 2007
Posts: 3
frankie7 is on a distinguished road (10)
i use avast, but by using this only tempoary, will it still disappear after i unistall this software ?

I am using windows XP.

Quote:
* Go to My Received Files in My Documents folder. Delete (Shift + Delete) the Photo Album.zip folder and its contents.
* Go to C:\Windows. Delete the Photo Album.zip folder.
* In C:\Windows\System, find the rdfhost.dll or rdshost.dll files. Delete them.
* Go to Start > Run. Type regedit to open the Registry. Navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She llServiceObjectDelayLoad
rdshost {5344BB88-3DE1-409F-8307-C85923A1F4DD} Delete this key (right-click and click on Delete)
* Navigate to HKCR\CLSID\{5344BB88-3DE1-409F-8307-C85923A1F4DD} Delete this key.
* Reboot your computer.
this part, the part that says

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She llServiceObjectDelayLoad
rdshost
Is not there. I have different settings.
Reply With Quote
Reply


LinkBacks (?)
LinkBack to this Thread: http://www.bigblueball.com/forums/windows-live-messenger-support/39945-photo-album-zip.html
Posted By For Type Date
Computer & IT计算机世界-[参加活动][原创]小心photo album.zip[Chinese In North America(北美华人e网)] This thread Refback 06-04-2007 02:50 AM
PPCSG > Virus ; PHOTO ZIP file This thread Refback 06-01-2007 08:15 AM
PPCSG > Virus ; PHOTO ZIP file This thread Refback 04-15-2007 06:29 PM
PPCSG -> Virus ; PHOTO ZIP file This thread Refback 04-12-2007 07:07 PM
Maple Story Buy and Sell - The Tech Support Thread - Get Help here This thread Refback 04-08-2007 05:05 PM
PPCSG -> Virus ; PHOTO ZIP file This thread Refback 04-08-2007 11:31 AM
WNQ. xD This thread Refback 04-06-2007 01:23 PM
PPCSG -> Virus ; PHOTO ZIP file This thread Refback 04-06-2007 02:41 AM

Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools


Similar Topics
Topic Topic Starter Forum Replies Last Post
Add a photo to people(s) listed in my Yahoo Messenger Friends List Dagget Yahoo! Messenger Support 1 06-11-2006 09:25 PM
How does photo sharing work in Y! Messenger? leoleoleo Yahoo! Messenger Support 2 02-27-2006 06:50 PM
Kodak Adds Photo Sharing to Skype Jeff VoIP News 0 01-09-2006 01:39 AM
Can One Add A Photo On BBB? Razincake Here! razincake Forum Support 7 08-18-2005 02:35 PM

 

All times are GMT -5. The time now is 01:16 PM.