Welcome to SecurityForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

How to get rid of ICQ.PWS.Trojan

 
   Security Forums (Home) -> General Discussions RSS
Next:  send me a virus or trojan please  
Author Message
philip

External


Since: Feb 24, 2004
Posts: 1



(Msg. 1) Posted: Tue Feb 24, 2004 8:19 pm
Post subject: How to get rid of ICQ.PWS.Trojan
Archived from groups: alt>comp>virus (more info?)

Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or
quarantine. it. Access denied. And my system is getting very slow. How can i
get rid of that trojan and the associated Worm.Win32.Bizex?

Thanks
philip

 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Big Will

External


Since: Feb 21, 2004
Posts: 40



(Msg. 2) Posted: Tue Feb 24, 2004 9:55 pm
Post subject: Re: How to get rid of ICQ.PWS.Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

philip wrote:

> Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or
> quarantine. it. Access denied. And my system is getting very slow. How can i
> get rid of that trojan and the associated Worm.Win32.Bizex?
>
> Thanks
> philip
>
>
1)What OS are you using? 2)Where is it located. If you're using
Windows XP, then you might need to purge system restore. Try purging
system restore, then rebooting and running in safe mode, and attempt the
scan then. Also, because Symantec doesn't provide much information on
this trojan, what's the actual filename that it appears under (include
full path). Chances are, you could just delete it, but since I don't
know much about this trojan, and Symantec isn't offering any
information, I can't tell you to simply delete the file without knowing
the consequences (unless someone else in this newsgroup is more familiar
with icq.pws.trojan). Also, you might want to look into TDS3
(tds3.diamondcs.com.au), a dedicated trojan removal program. Oh, and
when you finally delete the tojan, change your passwords, because this
one is a password stealer (pws=password steal).

--
William

If it don't work, hit it.
If it still doesn't work, kick it.
If it works after hitting it and kicking it, then it doesn't matter if
hitting it or kicking it helped, what's important is it worked.

 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Gabriele Neukam

External


Since: Sep 14, 2004
Posts: 462



(Msg. 3) Posted: Wed Feb 25, 2004 8:30 pm
Post subject: Re: How to get rid of ICQ.PWS.Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On that special day, philip, (pcywong@stanford.edu) said...

> NAV detected ICQ.PWS.Trojan but can't clean or
> quarantine. it.

The name is quite generic, it just says the heuristics found a trojan
that is specialized on using IRC (to announce a trojanized site) and log
passwords to send them to a place where someone will read and copy them.

> Access denied. And my system is getting very slow.

Which indicates that this trojan is running in the background, but with
high priority. Programs that are currently active, cannot be deleted (a
self protective scheme of XP). You will have to prevent the automatic
startup of the trojan in order to remove it, which means boot the PC in
Safe Mode.

And you will have to remove the trojan from the system backup aka system
restore, too, because files that are deleted, will be stored in that
backup, and reactivated later on, with the next start. The problem is,
you cannot exclude a single file from system restore; you have to
deactivate the system restore, reboot, so that the restore files are
wiped, and activate the system restore again.

I am only using Windows ME, and disabled this "feature" after a few
weeks, because I don't see much sense in keeping old configurations. If
I mess up the machine royally, I'll have to fix it from a boot disk, but
heck; I did that in former times, too, with older Win versions.

> How can i
> get rid of that trojan and the associated Worm.Win32.Bizex?

The Norton and other AV sites should by now give details on how to deal
with this worm.

And to prevent it from happening again: please switch to another
browser, like Mozilla Thunderbird. This worm was installed by a
trojanized site you went to.

Maybe you were lured there by a message sent by the trojan via IRC. But
there are drive-by infections, too, via ad banners; and even official
sites have already been infectious, as it has happened with a German
public service site last year, which had been hacked by intruders.


Gabriele Neukam

Gabriele.Spamfighter.Neukam.RemoveThis@t-online.de


--
Ah, Information. A good, too valuable these days, to give it away, just
so, at no cost.
 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Rod S

External


Since: Feb 19, 2004
Posts: 5



(Msg. 4) Posted: Wed Feb 25, 2004 8:40 pm
Post subject: Re: How to get rid of ICQ.PWS.Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

PWS is definately a password stealer. The reason your AV can't remove it is
that its probably still running. Find out what filename it is and path,
then run taskmanager and kill the process. Then delete the file or submit
it to your favourite AV companies.

If you're having problems killing the process, download TDS-3 (Trojan
Defence Suite) or Port Explorer (allows you to see where the trojan is
sending the passwords) from www.diamondcs.com.au.. Both allow the
termination of processes.

Before running a system scan, disable your AV (resident) and scan/remove
using TDS-3.

Let us know how that goes.

"Big Will"
<spamWspamispamlspamlspamBspam4spamespamvspaaaammespammityrspam@nidontlikesp
ametzero.net> wrote in message
> philip wrote:
>
> > Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or
> > quarantine. it. Access denied. And my system is getting very slow. How
can i
> > get rid of that trojan and the associated Worm.Win32.Bizex?
> >
> > Thanks
> > philip
> >
> >
> 1)What OS are you using? 2)Where is it located. If you're using
> Windows XP, then you might need to purge system restore. Try purging
> system restore, then rebooting and running in safe mode, and attempt the
> scan then. Also, because Symantec doesn't provide much information on
> this trojan, what's the actual filename that it appears under (include
> full path). Chances are, you could just delete it, but since I don't
> know much about this trojan, and Symantec isn't offering any
> information, I can't tell you to simply delete the file without knowing
> the consequences (unless someone else in this newsgroup is more familiar
> with icq.pws.trojan). Also, you might want to look into TDS3
> (tds3.diamondcs.com.au), a dedicated trojan removal program. Oh, and
> when you finally delete the tojan, change your passwords, because this
> one is a password stealer (pws=password steal).
>
> --
> William
>
> If it don't work, hit it.
> If it still doesn't work, kick it.
> If it works after hitting it and kicking it, then it doesn't matter if
> hitting it or kicking it helped, what's important is it worked.
>
 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
New Trojan? - Not sure what's up with my machine, but the spousal unit was on Ebay the other night and may have picked up something. I've noticed since then, when I've used Hotmail as well as our bank's website, the on-screen chars. and the typing lags behind...

trojan.svc.a - my avg anti virus resident sheild has come up with constant warnings 'backdoor trojan svc.a detectected' I can find no inf on this one-i ran avg it said it detected and healed but i went away for a while came back then it said same message. What is this....

PUP.exe Trojan? - I have been having some odd problems lately with my PC which seem to indicate a Trojan in onboard. On startup I get a 'new' .exe appearing in my C:\windows\system32 directory ervery time. It always has a different name (tblfiltu.exe, ssecd.exe,..

Trojan - I have a trojan, I can't quite remember the full message, something about a dialler, maybe windows dialler or something. AVG picks it up but won't fix it, s and b, cw shredder and Trojan Guarder Gold don't work. I know there's not much to work off..

Trojan need help please - Hi Asking this for a friend. My friend has a Trojan quarantined in Norton with the following numbers and letters no specific name to it A0008428-cpy Problem is it will not let her delete it. How can she delete it. Thanks Michelle
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]