Windows XP
--
Questions
--
Followers
Top Experts
I am running Ad-Aware as I am typing now. It shows there are 11 threats. I am afraid that if I delete or if the Ad-Aware fixs this, would it damage my Windows System files? Woill I be able to boot up normally? What precautions do I need to take to avoid a situation where fixing a virus ends up destroying the OS?
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
MRU Object: MRU Registry Key:S-1-5-21-884327365-381
Should I remove this object. It is a Registry key so I am concerned.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
It infects PE exe files. The virus can also act as a Network-Worm on machines with an unpatched DCOM RPC vulnerability. Microsoft Security Bulletin MX03-026 details the vulnerability. After launch, Tenga checks if the domain vx9.users.freebsd is available and attempts to dowload Trojan-Downloader.Win32.Sm
detailed information about the virus below
http://www.avira.com/en/threats/section/fulldetails/id_vir/2661/w32_stanit.html
http://www.eset.com.br/threat-center/msgs/tengaa.htm
to properly clean this up, try booting into Safe mode & run a full system scan with your antivirus
also you can double check if the listed registry keys still exist after the cleanup
HKLM\SOFTWARE\Microsoft\Wi
GAELICUM.EXE=<Path>\GAELICUM.EXE
and
HKLM\SOFTWARE\Microsoft\Wi
CBACK.EXE=<Path>\CBACK.EXE
It will be also a good idea to run an online scan using Kaspersky online scanner to ensure the infection is gone.
http://www.kaspersky.com/virusscanner
it also tries to spread via DCOM RPC Interface Buffer Overrun Vulnerability , which is a very old vulnerability
http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx
Chances are you are already patched, but you may want to ensure that your machines have the latest service packs & hotfixes installed.
hope this helps.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
But flubster was right. I was little impatient and over cautious... I paid the price :(. Thanks anyway.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Windows XP
--
Questions
--
Followers
Top Experts
Microsoft Windows XP is the sixth release of the NT series of operating systems, and was the first to be marketed in a variety of editions: XP Home and XP Professional, designed for business and power users. The advanced features in XP Professional are generally disabled in Home Edition, but are there and can be activated. There were two 64-bit editions, an embedded edition and a tablet edition.