Link to home
Create AccountLog in
Windows XP

Windows XP

--

Questions

--

Followers

Top Experts

Avatar of hpjethwa
hpjethwa

W32.Licum is detected. How do I safely remove it without damaging the Windows System file?
N360 found W32.Licum and wants a manual removal. In its Norton 360's Detail tab it notes that 1 file is affected. In file detail it notes: (___________) inside of [c:\windows\installer\1910b542.ms]
I am running Ad-Aware as I am typing now. It shows there are 11 threats. I am afraid that if I delete or if the Ad-Aware fixs this, would it damage my Windows System files? Woill I be able to boot up normally? What precautions do I need to take to avoid a situation where fixing a virus ends up destroying the OS?

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of flubbsterflubbster🇺🇸

A .msi file is an installer package and removing it will not harm your system. Worst case is that if the update or software that it installed ever has to be re-installed, you would have to download it again. Allow your antivirus to clean your system asap.

Avatar of hpjethwahpjethwa

ASKER

Thanks. Now I know that it will be OK to reboot without problems. Still I need to know I do I fix this virus.

Avatar of flubbsterflubbster🇺🇸

Just allow Norton antivirus to clean it. It is a low-level threat and should be no problem. If you do not have a good antivirus, may I suggest downloading avast! antivirus home edition. It is free and extremely powerful, easy to use, and very non-intrusive. I use that along with superantispyware free edition also. Together they are great.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Ad-Aware Scan Results shows:
MRU Object: MRU Registry Key:S-1-5-21-884327365-3810678138-1800662729-1005\Software\Microsoft\Search Assistant\ACMru\5603 Count:1
Should I remove this object. It is a Registry key so I am concerned.

Avatar of flubbsterflubbster🇺🇸

Yes, it can be removed. It stands for Most Recently Used (MRU), and is actually the last thing that you searched for. It is more a privacy issue than malware.

Also, maybe send us your HijackThis (http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php) log after. And maybe scan with Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam.php

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Mohamed OsamaMohamed Osama🇪🇬

This is an executable File infector Virus with Worm like behaviour ( W32.Licum ) aka W32. Tenga.a , aka W32.stanit

It infects PE exe files. The virus can also act as a Network-Worm on machines with an unpatched DCOM RPC vulnerability. Microsoft Security Bulletin MX03-026 details the vulnerability. After launch, Tenga checks if the domain vx9.users.freebsd is available and attempts to dowload Trojan-Downloader.Win32.Small.bdc from http://**nt*.lycos.it/v**/dl.exe Tenga is a classic appending virus that increases the size of infected files by 3 KB.
detailed information about the virus below
http://www.avira.com/en/threats/section/fulldetails/id_vir/2661/w32_stanit.html

http://www.eset.com.br/threat-center/msgs/tengaa.htm

to properly clean this up, try booting into Safe mode & run a full system scan with your antivirus
also you can double check if the listed registry keys still exist after the cleanup 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
GAELICUM.EXE=<Path>\GAELICUM.EXE

and

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
CBACK.EXE=<Path>\CBACK.EXE

It will be also a good idea to run an online scan using Kaspersky online scanner to ensure the infection is gone.
http://www.kaspersky.com/virusscanner


it also tries to spread via DCOM RPC Interface Buffer Overrun Vulnerability , which is a very old vulnerability 

http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx
Chances are you are already patched, but you may want to ensure that your machines have the latest service packs & hotfixes installed.

hope this helps.




Attached is the Log file for Hijackthis.
What should I do next?
hijackthis.log

Do you still have problems? Your log seems clean.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


is Norton still detecting anything ?

Yes, Norton 360 still detectes it. If I try to run N369 in safe mode it displays "N360 cannot run in run mode". I ran Superanti spyware in safe mode, but it could not detect anything. I ran Malwaerbites, but it could not find W32.Licum.

ASKER CERTIFIED SOLUTION
Avatar of flubbsterflubbster🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Yes I got online with Nortons Support. (They charged me $99). The tech just went ahead in C:\windows \installer and just deleted the file. Thats it.
But flubster was right. I was little impatient and over cautious... I paid the price :(.   Thanks anyway.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.

Windows XP

Windows XP

--

Questions

--

Followers

Top Experts

Microsoft Windows XP is the sixth release of the NT series of operating systems, and was the first to be marketed in a variety of editions: XP Home and XP Professional, designed for business and power users. The advanced features in XP Professional are generally disabled in Home Edition, but are there and can be activated. There were two 64-bit editions, an embedded edition and a tablet edition.