Thanks
Downloader.Wren.k
#1 OFFLINE
Posted 22 June 2006 - 06:33 PM
Thanks
#2 OFFLINE
Posted 22 June 2006 - 06:38 PM
http://www.piriform.com/docs
#3 OFFLINE
Posted 22 June 2006 - 06:46 PM
#4 OFFLINE
Posted 22 June 2006 - 06:49 PM
http://www.viruslist.com/en/viruses/encycl...a?virusid=79663
http://www.piriform.com/docs
#5 OFFLINE
Posted 22 June 2006 - 06:51 PM
Thanks again.
#6 OFFLINE
Posted 22 June 2006 - 07:01 PM
Sorry I don't now about how would be best to remove it.
http://www.piriform.com/docs
#7 OFFLINE
Posted 22 June 2006 - 07:15 PM
hazelnut, on Jun 22 2006, 02:01 PM, said:
Sorry I don't now about how would be best to remove it.
The question stands for anyone who knows!
#8 OFFLINE
Posted 22 June 2006 - 07:37 PM
It would be best to post a Hijack This log in the appropriate section of this board, so that someone could have a look at your configuration.
File names vary wildly among variants, and "yours" may have a totally different name.
If the run entry is there it will show up among the "O4's" in the log and will itself be easy to remove that way.
You may also turn out to have more requiring attention.
#9 OFFLINE
Posted 22 June 2006 - 08:19 PM
I will try to post a HJT log, but it isn't my pc. It's my boss's pc and he gets nervous about things that he's never heard of before. He said he'll think about the HJT log...so until then!
I am trying to get information about the type of infections on the pc, hoping that it will make him want to take more steps in cleaning it.
#10 OFFLINE
Posted 22 June 2006 - 08:23 PM
krit86lr, on Jun 22 2006, 10:19 PM, said:
It's my boss's pc and he gets nervous about things that he's never heard of before. He said he'll think about the HJT log...so until then!
Well, it's a very useful diagnostic tool, and if your boss wants us to offer any meaningful advice, the more information the better...
Also, should the log turn up a couple of issues, it's much preferable to have HT 'fix' them, then to have to go and edit the registry manually.
And don't forget that HT backs up everything it removes/fixes.
Hope those arguments will help convince him...
#11 OFFLINE
Posted 22 June 2006 - 08:49 PM
TonyKlein, on Jun 22 2006, 03:23 PM, said:
I've cleaned/protected (with Andy's help) 3 machines on the network which totalled over 500 infections, but none of the main machines have been cleaned.
I wish that people would just do as they're told sometimes!!!!
Later, wish me luck!
#12 OFFLINE
Posted 22 June 2006 - 11:20 PM
Quote
Good luck, K.
#13 OFFLINE
Posted 23 June 2006 - 03:13 PM
So I'm running some more scanners before posting a HJT log. I have one question though. There are 3 drives, so do I need to run the scanners on all of the disks and post a HJT log for all 3 drives?
Thanks.
#14 OFFLINE
Posted 23 June 2006 - 04:42 PM
Otherwise, no.
#15 OFFLINE
Posted 23 June 2006 - 06:41 PM
I keep trying to scan with Adaware, but it keeps causing a Delayed Write Failure on the Network Disk. What do I do?
Is it possible that if this keeps happening that it can harm the drive? Should I just leave it alone?
Thanks in advance.
#16 OFFLINE
Posted 23 June 2006 - 06:55 PM
krit86lr, on Jun 23 2006, 08:41 PM, said:
Probably because the file is in use or protected in some way. Once again, without a HijackThis log we don't know what we're looking at.
Quote
No idea; it's a new one to me...
Quote
Very unlikely.
I think the priority now lies in removing that worm Ewido found. And unless we see a HijackThis log we'll never know if there's any additional malware that Ewido did NOT detect...
#17 OFFLINE
Posted 23 June 2006 - 11:29 PM
A downloader is a small simple program, when runned it downloads a executable (.exe) file from the Internet, usually via HTTP (web) and then executes it. That file it download is usually a malicious file such as an bot (botnet/dosbot) or spyware.
Having an outbound firewall that detects outgoing connections might be a good idea (though, sometimes they can be tricked (leaktest)).
#18 OFFLINE
Posted 25 June 2006 - 06:42 PM
Eldmannen, on Jun 23 2006, 06:29 PM, said:
















