Jump to content


Downloader.Wren.k


  • You cannot reply to this topic
17 replies to this topic

#1 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 22 June 2006 - 06:33 PM

Does anyone know what "Downloader.Wren.k" is? I googled it, and nothing came up.

Thanks :)

#2 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,458 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 22 June 2006 - 06:38 PM

You could try this page krit,

http://www.viruslist.com/en/viruses/encycl...a?virusid=89393
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#3 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 22 June 2006 - 06:46 PM

Thank you Hazelnut! :D

#4 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,458 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 22 June 2006 - 06:49 PM

Also look here as they are apparently related

http://www.viruslist.com/en/viruses/encycl...a?virusid=79663
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#5 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 22 June 2006 - 06:51 PM

So cleaning out the temp files and removing that reg key should get rid of it entirely? That's my logical assumption, but I just wanted to confirm.

Thanks again. :)

#6 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,458 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 22 June 2006 - 07:01 PM

Krit, I'm a link finder,
Sorry I don't now about how would be best to remove it. :)
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#7 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 22 June 2006 - 07:15 PM

View Posthazelnut, on Jun 22 2006, 02:01 PM, said:

Krit, I'm a link finder,
Sorry I don't now about how would be best to remove it. :)
LOL, Thanks for the links. They are very helpful. :)

The question stands for anyone who knows!

#8 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 22 June 2006 - 07:37 PM

Removing only the Registry Run entry won't probably be all that's required.

It would be best to post a Hijack This log in the appropriate section of this board, so that someone could have a look at your configuration.

File names vary wildly among variants, and "yours" may have a totally different name.
If the run entry is there it will show up among the "O4's" in the log and will itself be easy to remove that way.

You may also turn out to have more requiring attention.

#9 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 22 June 2006 - 08:19 PM

Thank you.

I will try to post a HJT log, but it isn't my pc. It's my boss's pc and he gets nervous about things that he's never heard of before. He said he'll think about the HJT log...so until then!

I am trying to get information about the type of infections on the pc, hoping that it will make him want to take more steps in cleaning it. ;)

#10 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 22 June 2006 - 08:23 PM

View Postkrit86lr, on Jun 22 2006, 10:19 PM, said:


It's my boss's pc and he gets nervous about things that he's never heard of before. He said he'll think about the HJT log...so until then!

Well, it's a very useful diagnostic tool, and if your boss wants us to offer any meaningful advice, the more information the better...

Also, should the log turn up a couple of issues, it's much preferable to have HT 'fix' them, then to have to go and edit the registry manually.

And don't forget that HT backs up everything it removes/fixes.

Hope those arguments will help convince him... ;)

#11 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 22 June 2006 - 08:49 PM

View PostTonyKlein, on Jun 22 2006, 03:23 PM, said:

Hope those arguments will help convince him... ;)
Thank you. I have given him that information so far, and he's still be hesitant so now I've moved on to scare tactics. LOL

I've cleaned/protected (with Andy's help) 3 machines on the network which totalled over 500 infections, but none of the main machines have been cleaned.

I wish that people would just do as they're told sometimes!!!! :P lmao


Later, wish me luck!

#12 OFFLINE   Woody

    Advanced Member

  • Members
  • PipPipPip
  • 457 posts
  • Gender:Male
  • Location:Manchester. UK

Posted 22 June 2006 - 11:20 PM

Quote

Later, wish me luck!

Good luck, K. :)
It is never difficult to distinguish between a Scotsman with a grievance and a ray of sunshine. P. G. Wodehouse

#13 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 23 June 2006 - 03:13 PM

Okay, I won the battle. hehe

So I'm running some more scanners before posting a HJT log. I have one question though. There are 3 drives, so do I need to run the scanners on all of the disks and post a HJT log for all 3 drives?

Thanks. :D

#14 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 23 June 2006 - 04:42 PM

If you have operating systems installed on all three the drives, yes please.

Otherwise, no.

#15 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 23 June 2006 - 06:41 PM

Okay. I finished a scan with SpyBot, CWShredder, and Ewido. Ewido couldn't remove 1 worm and I don't know why. I used CCleaner, installed an AV and Spyware Blaster.

I keep trying to scan with Adaware, but it keeps causing a Delayed Write Failure on the Network Disk. What do I do?

Is it possible that if this keeps happening that it can harm the drive? Should I just leave it alone?

Thanks in advance. :)

#16 OFFLINE   TonyKlein

    Power Member

  • Spyware Moderators
  • 606 posts
  • Gender:Male
  • Location:Netherlands

Posted 23 June 2006 - 06:55 PM

View Postkrit86lr, on Jun 23 2006, 08:41 PM, said:

I finished a scan with SpyBot, CWShredder, and Ewido. Ewido couldn't remove 1 worm and I don't know why.

Probably because the file is in use or protected in some way. Once again, without a HijackThis log we don't know what we're looking at.

Quote

I keep trying to scan with Adaware, but it keeps causing a Delayed Write Failure on the Network Disk. What do I do?

No idea; it's a new one to me...

Quote

Is it possible that if this keeps happening that it can harm the drive?

Very unlikely.

I think the priority now lies in removing that worm Ewido found. And unless we see a HijackThis log we'll never know if there's any additional malware that Ewido did NOT detect...

#17 OFFLINE   Eldmannen

    Annoyance

  • Banned
  • PipPipPipPipPip
  • 2,198 posts
  • Location:Internet
  • Interests:Free software, open-source, GNU GPL, Linux, security, encryption, privacy, anonymity.

Posted 23 June 2006 - 11:29 PM

Sounds like a "downloader".
A downloader is a small simple program, when runned it downloads a executable (.exe) file from the Internet, usually via HTTP (web) and then executes it. That file it download is usually a malicious file such as an bot (botnet/dosbot) or spyware.

Having an outbound firewall that detects outgoing connections might be a good idea (though, sometimes they can be tricked (leaktest)).



#18 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 25 June 2006 - 06:42 PM

View PostEldmannen, on Jun 23 2006, 06:29 PM, said:

Having an outbound firewall that detects outgoing connections might be a good idea (though, sometimes they can be tricked (leaktest)).
Can't really do that on this PC.