Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

How to get rid of ICQ.PWS.Trojan

 
   Security Forums (Home) -> General Discussions RSS
Next:  send me a virus or trojan please  
Author Message
philip

External


Since: Feb 24, 2004
Posts: 1



(Msg. 1) Posted: Tue Feb 24, 2004 8:19 pm
Post subject: How to get rid of ICQ.PWS.Trojan
Archived from groups: alt>comp>virus (more info?)

Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or
quarantine. it. Access denied. And my system is getting very slow. How can i
get rid of that trojan and the associated Worm.Win32.Bizex?

Thanks
philip

 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Big Will

External


Since: Feb 21, 2004
Posts: 40



(Msg. 2) Posted: Tue Feb 24, 2004 9:55 pm
Post subject: Re: How to get rid of ICQ.PWS.Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

philip wrote:

> Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or
> quarantine. it. Access denied. And my system is getting very slow. How can i
> get rid of that trojan and the associated Worm.Win32.Bizex?
>
> Thanks
> philip
>
>
1)What OS are you using? 2)Where is it located. If you're using
Windows XP, then you might need to purge system restore. Try purging
system restore, then rebooting and running in safe mode, and attempt the
scan then. Also, because Symantec doesn't provide much information on
this trojan, what's the actual filename that it appears under (include
full path). Chances are, you could just delete it, but since I don't
know much about this trojan, and Symantec isn't offering any
information, I can't tell you to simply delete the file without knowing
the consequences (unless someone else in this newsgroup is more familiar
with icq.pws.trojan). Also, you might want to look into TDS3
(tds3.diamondcs.com.au), a dedicated trojan removal program. Oh, and
when you finally delete the tojan, change your passwords, because this
one is a password stealer (pws=password steal).

--
William

If it don't work, hit it.
If it still doesn't work, kick it.
If it works after hitting it and kicking it, then it doesn't matter if
hitting it or kicking it helped, what's important is it worked.

 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Gabriele Neukam

External


Since: Sep 14, 2004
Posts: 462



(Msg. 3) Posted: Wed Feb 25, 2004 8:30 pm
Post subject: Re: How to get rid of ICQ.PWS.Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On that special day, philip, (pcywong@stanford.edu) said...

> NAV detected ICQ.PWS.Trojan but can't clean or
> quarantine. it.

The name is quite generic, it just says the heuristics found a trojan
that is specialized on using IRC (to announce a trojanized site) and log
passwords to send them to a place where someone will read and copy them.

> Access denied. And my system is getting very slow.

Which indicates that this trojan is running in the background, but with
high priority. Programs that are currently active, cannot be deleted (a
self protective scheme of XP). You will have to prevent the automatic
startup of the trojan in order to remove it, which means boot the PC in
Safe Mode.

And you will have to remove the trojan from the system backup aka system
restore, too, because files that are deleted, will be stored in that
backup, and reactivated later on, with the next start. The problem is,
you cannot exclude a single file from system restore; you have to
deactivate the system restore, reboot, so that the restore files are
wiped, and activate the system restore again.

I am only using Windows ME, and disabled this "feature" after a few
weeks, because I don't see much sense in keeping old configurations. If
I mess up the machine royally, I'll have to fix it from a boot disk, but
heck; I did that in former times, too, with older Win versions.

> How can i
> get rid of that trojan and the associated Worm.Win32.Bizex?

The Norton and other AV sites should by now give details on how to deal
with this worm.

And to prevent it from happening again: please switch to another
browser, like Mozilla Thunderbird. This worm was installed by a
trojanized site you went to.

Maybe you were lured there by a message sent by the trojan via IRC. But
there are drive-by infections, too, via ad banners; and even official
sites have already been infectious, as it has happened with a German
public service site last year, which had been hacked by intruders.


Gabriele Neukam

Gabriele.Spamfighter.Neukam DeleteThis @t-online.de


--
Ah, Information. A good, too valuable these days, to give it away, just
so, at no cost.
 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Rod S

External


Since: Feb 19, 2004
Posts: 5



(Msg. 4) Posted: Wed Feb 25, 2004 8:40 pm
Post subject: Re: How to get rid of ICQ.PWS.Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

PWS is definately a password stealer. The reason your AV can't remove it is
that its probably still running. Find out what filename it is and path,
then run taskmanager and kill the process. Then delete the file or submit
it to your favourite AV companies.

If you're having problems killing the process, download TDS-3 (Trojan
Defence Suite) or Port Explorer (allows you to see where the trojan is
sending the passwords) from www.diamondcs.com.au.. Both allow the
termination of processes.

Before running a system scan, disable your AV (resident) and scan/remove
using TDS-3.

Let us know how that goes.

"Big Will"
<spamWspamispamlspamlspamBspam4spamespamvspaaaammespammityrspam@nidontlikesp
ametzero.net> wrote in message news:403c394c$1@darkstar...
> philip wrote:
>
> > Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or
> > quarantine. it. Access denied. And my system is getting very slow. How
can i
> > get rid of that trojan and the associated Worm.Win32.Bizex?
> >
> > Thanks
> > philip
> >
> >
> 1)What OS are you using? 2)Where is it located. If you're using
> Windows XP, then you might need to purge system restore. Try purging
> system restore, then rebooting and running in safe mode, and attempt the
> scan then. Also, because Symantec doesn't provide much information on
> this trojan, what's the actual filename that it appears under (include
> full path). Chances are, you could just delete it, but since I don't
> know much about this trojan, and Symantec isn't offering any
> information, I can't tell you to simply delete the file without knowing
> the consequences (unless someone else in this newsgroup is more familiar
> with icq.pws.trojan). Also, you might want to look into TDS3
> (tds3.diamondcs.com.au), a dedicated trojan removal program. Oh, and
> when you finally delete the tojan, change your passwords, because this
> one is a password stealer (pws=password steal).
>
> --
> William
>
> If it don't work, hit it.
> If it still doesn't work, kick it.
> If it works after hitting it and kicking it, then it doesn't matter if
> hitting it or kicking it helped, what's important is it worked.
>
 >> Stay informed about: How to get rid of ICQ.PWS.Trojan 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Damn trojan in my temp (probably). Advice needed. - Ok , this is how the situation has. 3 days my firewall poped up and an application in my C:\Documents And Settings\Administrator\Local Settings\temp wanted to connect at port 80 of an address. It had a weird icon and a weird name ( Rar1.exe). I denied....

Running a trojan program and Virus programs a waste of time? - Thanks for opinions of the knowledgable ones:>) Regards Buddy B

Poss trojan? - I just updated my AVG database, and it picked up a back door Ap trojan. Details are: C:\Windows\system32\XUDERSD.exe. When I try to remove it to quarantine, a message says the file cannot be removed. I checked it with V.3.5 of The Cleaner, which doesn't...

church trojan - Last week it was discovered our church computer(s) have a trojan virus. There are three networked together. The internet provider phoned the secretary and told her that a port was open. I looked for suspicious .exe files and found "pipecmdsvr.exe&q...

deltee trojan - hi all ive just done a full system virus check and Norton has found what it calls the deltree trojan, it says the file it has infected (delete.bat) cannot be repaired or deleted so its been put into quarantine. what do i do now, can i leave it there..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]