If you are an Iban or familiar with Iban language you will be laughing…
don’t forget to leave a comment about it..
Photo Album2007.pif : a MSN virus.
I was infected.. darn…
the behavior of the virus: as written here and from my observation.
>will save a copy of photo album.zip in C:\WINDOWS\, that zip file contain the same virus. ready to spread.
>create a new file in C:\WINDOWS\system32, rdshost.dll
>change your registry KEY.
[ Changes to registry ]
* Sets value “rdshost”=”{000000-0050-DF1000″ in key “HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad”.
* Creates key “HKCR\CLSID\{000000-0050-DF1000\InProcServer32″.
* Sets value “default”=”rdshost.dll” in key “HKCR\CLSID\{000000-0050-DF1000\InProcServer32″.
HKLM = HKey Local Machine; HKCR = HKey CLASS ROOT
(taken from here)
>if left untreated, it will infect other people in your buddy list.
My Solution:
>find the photo album.zip in C:\WINDOWS\ and delete it..
> find the rdshost.dll file in C:\WINDOWS\system32. and force delete it. Use Unlocker. Install it and right-click rdshost.dll > unlocker.
> then you can delete it. HOHOHOO…..
> then Start>Run> regedit
>press Ctrl+F to use the search function. type in rdshost.dll and search it…
>Actually..I delete all rdshost.dll key that I found…
> search again, press F3 to do this.. until you deleted all the rdshost.dll keys..
>now you should be ok I guess…
if you are not, we are both screwed…
UPDATE: My friend was infected by the same Photo Album2007.pif file, but the rdshost.dll file does not exist in the C:\WINDOWS\system32 directory, but instead a rdihost.dll file was found, upon further checking, rdihost.dll is not native to the Window folder. So I assume it is the virus, and was deleted..
Take note: please install an antivirus software and update it regularly. Do not use cracked antivirus. Head to these link to get a free antivirus:
Avast Home Edition
A free Home Edition for the Avast
free AVG
Another free alternative from Grisoft
Malaysian Internet: Towards the 1st world status
Hm…
well.. Half of the company email that I emailed is not functioning, whether dead or or full and, sadly some of them are government agency.. negligence… can you imagine how much they have lost from a not working email….
still far from the 1st world status…
I never knew….
For heaven is so great. HB is back guys…..
fireelements.com
check it out…
w00t!!!!!!!!!!!




