This is kind of old stuff. but its been going around recently, as i know, since it was hit with my system.
I've been doing scans all night so far, and i just want to say If you get a message with a link in it randomly with your screenname and something about a photo...DONT OPEN IT.
it will try to save a file to your comupter then drive the comptuer nuts while it sends a link to all of your contacts.
its a root trojan.
Name wkssvc.exe
Description
Wkssvc.exe is Trojan/Backdoor Sdbot.
Kill the process wkssvc.exe and remove wkssvc.exe from Windows startup.
SOURCEim still trying to permanently delete it, but to stop it from starting over go to task manager (CRTL ALT DEL) and go to the processes tab and go to "wkssvc.exe" and right click on it and click end process. you'll get a warning but click yes end process. then go to Start menu then Run. in the run box type "msconfig" (without the quote marks) and when the window opens go to the startup tab and scroll down and uncheck the wkssvc.exe and hit apply, then ok. it will ask if you want to restart, i hit exit without restart, i'll do that later. when i actually get it to delete i'll post up how.
Good luck and hope you dont get this too. I use AVG free and zone alarm, and neither recognized it..during scans or anything.I also used spybot and adaware 2007 with no luck. so im just posting up to tell everyone.
starship_troopers