On that special day, philip, (pcywong@stanford.edu) said...
> NAV detected ICQ.PWS.Trojan but can't clean or
> quarantine. it.
The name is quite generic, it just says the heuristics found a trojan
that is specialized on using IRC (to announce a trojanized site) and log
passwords to send them to a place where someone will read and copy them.
> Access denied. And my system is getting very slow.
Which indicates that this trojan is running in the background, but with
high priority. Programs that are currently active, cannot be deleted (a
self protective scheme of XP). You will have to prevent the automatic
startup of the trojan in order to remove it, which means boot the PC in
Safe Mode.
And you will have to remove the trojan from the system backup aka system
restore, too, because files that are deleted, will be stored in that
backup, and reactivated later on, with the next start. The problem is,
you cannot exclude a single file from system restore; you have to
deactivate the system restore, reboot, so that the restore files are
wiped, and activate the system restore again.
I am only using Windows ME, and disabled this "feature" after a few
weeks, because I don't see much sense in keeping old configurations. If
I mess up the machine royally, I'll have to fix it from a boot disk, but
heck; I did that in former times, too, with older Win versions.
> How can i
> get rid of that trojan and the associated Worm.Win32.Bizex?
The Norton and other AV sites should by now give details on how to deal
with this worm.
And to prevent it from happening again: please switch to another
browser, like Mozilla Thunderbird. This worm was installed by a
trojanized site you went to.
Maybe you were lured there by a message sent by the trojan via IRC. But
there are drive-by infections, too, via ad banners; and even official
sites have already been infectious, as it has happened with a German
public service site last year, which had been hacked by intruders.
Gabriele Neukam
Gabriele.Spamfighter.Neukam DeleteThis @t-online.de
--
Ah, Information. A good, too valuable these days, to give it away, just
so, at no cost.
>> Stay informed about: How to get rid of ICQ.PWS.Trojan