<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: W32.Downadup</title> <atom:link href="http://www.precisesecurity.com/threats/worms/w32downadup/feed" rel="self" type="application/rss+xml" /><link>http://www.precisesecurity.com/worms/w32downadup</link> <description></description> <lastBuildDate>Thu, 09 Feb 2012 05:23:27 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: zee</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-4488</link> <dc:creator>zee</dc:creator> <pubDate>Thu, 24 Dec 2009 03:23:24 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-4488</guid> <description>i tried almost all the solutions from you guys but it didnt work.. after deleting the worm and it came back..help me</description> <content:encoded><![CDATA[<p>i tried almost all the solutions from you guys but it didnt work.. after deleting the worm and it came back..help me</p> ]]></content:encoded> </item> <item><title>By: Dayalan</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-4159</link> <dc:creator>Dayalan</dc:creator> <pubDate>Fri, 06 Nov 2009 10:06:21 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-4159</guid> <description>hi,
please help i need some help to remove Downadup.
i tried Malewerebytes,the symantec tool, the f-secure tool even the bit defender...checked the registry and no sign there...any other ideas?</description> <content:encoded><![CDATA[<p>hi,<br
/> please help i need some help to remove Downadup.<br
/> i tried Malewerebytes,the symantec tool, the f-secure tool even the bit defender&#8230;checked the registry and no sign there&#8230;any other ideas?</p> ]]></content:encoded> </item> <item><title>By: amar</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-4088</link> <dc:creator>amar</dc:creator> <pubDate>Tue, 27 Oct 2009 15:09:45 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-4088</guid> <description>if we format the laptop, can it delete the worm?</description> <content:encoded><![CDATA[<p>if we format the laptop, can it delete the worm?</p> ]]></content:encoded> </item> <item><title>By: PC Antivirus Update</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-3934</link> <dc:creator>PC Antivirus Update</dc:creator> <pubDate>Sat, 10 Oct 2009 12:15:18 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-3934</guid> <description>Hi
Thanks for sharing useful information about W32.Downadup. But i suggest Best Virus Protection software. This software fully protects your Computer .</description> <content:encoded><![CDATA[<p>Hi<br
/> Thanks for sharing useful information about W32.Downadup. But i suggest Best Virus Protection software. This software fully protects your Computer .</p> ]]></content:encoded> </item> <item><title>By: Emy</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-3218</link> <dc:creator>Emy</dc:creator> <pubDate>Mon, 10 Aug 2009 11:04:07 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-3218</guid> <description>I&#039;ve got a Flush Memory from China, found it on Ebay and when i put into my laptop Avira came out saying about that W32.Downadup.B worm. Cleaned it and that&#039;s it. everything is fine</description> <content:encoded><![CDATA[<p>I&#8217;ve got a Flush Memory from China, found it on Ebay and when i put into my laptop Avira came out saying about that W32.Downadup.B worm. Cleaned it and that&#8217;s it. everything is fine</p> ]]></content:encoded> </item> <item><title>By: precisesecurity</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-2504</link> <dc:creator>precisesecurity</dc:creator> <pubDate>Sun, 26 Apr 2009 11:53:43 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-2504</guid> <description>Formatting is the least thing that should be done. But if you are willing to format, it can remove the threat.</description> <content:encoded><![CDATA[<p>Formatting is the least thing that should be done. But if you are willing to format, it can remove the threat.</p> ]]></content:encoded> </item> <item><title>By: abigail</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-2478</link> <dc:creator>abigail</dc:creator> <pubDate>Wed, 22 Apr 2009 16:00:35 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-2478</guid> <description>If we format the laptop, can it delete the worm?</description> <content:encoded><![CDATA[<p>If we format the laptop, can it delete the worm?</p> ]]></content:encoded> </item> <item><title>By: Stephen Tzintzis</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-2418</link> <dc:creator>Stephen Tzintzis</dc:creator> <pubDate>Wed, 01 Apr 2009 20:15:41 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-2418</guid> <description>After spending almost 3 weeks virtually devoting all my time on understanding, studying, and researching this virus I&#039;ve finally come up with the best utilities and steps to overcome this stubborn worm.There are currently three variants of the virus, .A,.B, and .C.
Of the three .C is the hardest to inoculate, with .B being the most widespread.How do I know if I&#039;m infected with .B or .C?It&#039;s pretty simple. If you managed to download MS security patch and various scanners/cleaning utilities that don&#039;t run when you open them (i.e., the open and close extremely quickly, processes being killed by the virus) and if you tried booting into Safe Mode but couldn&#039;t then you most certainly have the .C variant of the virus lurking on your PC. If you&#039;ve noticed this happen on your PC and are having a nightmare to remove it (the way I had) the proceed to the .C Clean and Removal Steps below..B is fairly simple to remove/clean.  Therefore I&#039;ll start with.B Clean and Removal Steps
-------------------------------------
(a) download the following four files
(1)- http: //iv.cs.uni-bonn.de/uploads/media/conficker_mem_killer.exe
(2)- http: //iv.cs.uni-bonn.de/uploads/media/regnfile_01.exe
(3)- http: //www.bdtools.net/download/bd_rem_tool.zip
(4)- http: //www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
and download the appropriate MS-Hot Fix for your Operating System(b) if you cannot get to one or any of the above links, stop your DNS Client Service(c) boot the PC in Safe Mode(d) run conficker_mem_killer.exe, then run regnfile_01.exe, then bd_rem_tool_console.exe (unzipped from the bd_rem_tool.zip files), and then finally patch the system with the appropriate MS-Hot Fix you downloaded.(e) reboot in normal mode and re-run all those files except for the patch again(f) Go to your Services and Start and set the following services to Automaitc
- Windows Update
- BITS
- Error Reporting
- Security Server (if applicable)
- Windows Firewall(g) For extended protection, stop the Computer Browser service and set it to Disabled(h) For extended protection, stop the Task Scheduler service and set it to Disabled(i) For extended protection, stop the Server service (and any dependant services) and set it to Disabled (note that if your PC needs to share files or printers this service must be started and set to automatic)(j) Enable your Windows Firewall and set the appropriate Exceptions you need (highly recommended)(k) apply the latest Windows Service Pack and Fully Windows Update your PC (absolutely required)(l) Set Windows Update to run daily and automatically update your PC
- open gpedit.msc (start&gt;run and type in &#039;gpedit.msc&#039;) if you&#039;re using XP SP2+ and go to Computer Configuration&gt;Administrative Templates&gt;Windows Components&gt;Windows Update&gt;No Auto Restart .... (Enable) so that after windows updates your PC automatically in the background it WILL NOT automatically restart the PC if there is a currently logged on user. (highly recommended)(n)  if you want to take furthere preventative measures disable autorun by going to gpedit.msc and go to
Computer Configuration&gt;Administrative Templates&gt;Windows Components&gt;System&gt;Turn Off Autoplay (Enable)(o) Install the latest version of your Antivirus Software and make the virus definitions are fully updated and set to check and install updates daily. (highly recommended).C Clean and Removal Steps
-------------------------------------
Do steps (a) and (b) as in the .B Removal Steps.Now you just need to get your PC to boot into Safe.To do so you need to get the Safe Mode registry keys from a like PC (O/S), export them from there and then import them on the infected PC.This should allow you to boot into safe Mode on the infected PC.Once you&#039;re in safe Mode you can proceed with steps (c) onward without any problems.The SafeMode keys you need to get are located in:
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
Export the entire SafeBoot Hive (folder)To import this file on the infected PC, simply double click on the .REG file you just exported.The .C variant also prevents you from viewing hidden files on your PC.
The following Batch file should resolve this problem:@ECHO OFF
BREAK ON
reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v CheckedValue /t REG_DWORD /d 0x1 /f
pause
exitGood Luck.</description> <content:encoded><![CDATA[<p>After spending almost 3 weeks virtually devoting all my time on understanding, studying, and researching this virus I&#8217;ve finally come up with the best utilities and steps to overcome this stubborn worm.</p><p>There are currently three variants of the virus, .A,.B, and .C.<br
/> Of the three .C is the hardest to inoculate, with .B being the most widespread.</p><p>How do I know if I&#8217;m infected with .B or .C?</p><p>It&#8217;s pretty simple. If you managed to download MS security patch and various scanners/cleaning utilities that don&#8217;t run when you open them (i.e., the open and close extremely quickly, processes being killed by the virus) and if you tried booting into Safe Mode but couldn&#8217;t then you most certainly have the .C variant of the virus lurking on your PC. If you&#8217;ve noticed this happen on your PC and are having a nightmare to remove it (the way I had) the proceed to the .C Clean and Removal Steps below.</p><p>.B is fairly simple to remove/clean.  Therefore I&#8217;ll start with</p><p>.B Clean and Removal Steps<br
/> &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br
/> (a) download the following four files<br
/> (1)- http: //iv.cs.uni-bonn.de/uploads/media/conficker_mem_killer.exe<br
/> (2)- http: //iv.cs.uni-bonn.de/uploads/media/regnfile_01.exe<br
/> (3)- http: //www.bdtools.net/download/bd_rem_tool.zip<br
/> (4)- http: //www.microsoft.com/technet/security/Bulletin/MS08-067.mspx<br
/> and download the appropriate MS-Hot Fix for your Operating System</p><p>(b) if you cannot get to one or any of the above links, stop your DNS Client Service</p><p>(c) boot the PC in Safe Mode</p><p>(d) run conficker_mem_killer.exe, then run regnfile_01.exe, then bd_rem_tool_console.exe (unzipped from the bd_rem_tool.zip files), and then finally patch the system with the appropriate MS-Hot Fix you downloaded.</p><p>(e) reboot in normal mode and re-run all those files except for the patch again</p><p>(f) Go to your Services and Start and set the following services to Automaitc<br
/> &#8211; Windows Update<br
/> &#8211; BITS<br
/> &#8211; Error Reporting<br
/> &#8211; Security Server (if applicable)<br
/> &#8211; Windows Firewall</p><p>(g) For extended protection, stop the Computer Browser service and set it to Disabled</p><p>(h) For extended protection, stop the Task Scheduler service and set it to Disabled</p><p>(i) For extended protection, stop the Server service (and any dependant services) and set it to Disabled (note that if your PC needs to share files or printers this service must be started and set to automatic)</p><p>(j) Enable your Windows Firewall and set the appropriate Exceptions you need (highly recommended)</p><p>(k) apply the latest Windows Service Pack and Fully Windows Update your PC (absolutely required)</p><p>(l) Set Windows Update to run daily and automatically update your PC<br
/> &#8211; open gpedit.msc (start&gt;run and type in &#8216;gpedit.msc&#8217;) if you&#8217;re using XP SP2+ and go to Computer Configuration&gt;Administrative Templates&gt;Windows Components&gt;Windows Update&gt;No Auto Restart &#8230;. (Enable) so that after windows updates your PC automatically in the background it WILL NOT automatically restart the PC if there is a currently logged on user. (highly recommended)</p><p>(n)  if you want to take furthere preventative measures disable autorun by going to gpedit.msc and go to<br
/> Computer Configuration&gt;Administrative Templates&gt;Windows Components&gt;System&gt;Turn Off Autoplay (Enable)</p><p>(o) Install the latest version of your Antivirus Software and make the virus definitions are fully updated and set to check and install updates daily. (highly recommended)</p><p>.C Clean and Removal Steps<br
/> &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br
/> Do steps (a) and (b) as in the .B Removal Steps.</p><p>Now you just need to get your PC to boot into Safe.</p><p>To do so you need to get the Safe Mode registry keys from a like PC (O/S), export them from there and then import them on the infected PC.</p><p>This should allow you to boot into safe Mode on the infected PC.</p><p>Once you&#8217;re in safe Mode you can proceed with steps (c) onward without any problems.</p><p>The SafeMode keys you need to get are located in:<br
/> HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot<br
/> Export the entire SafeBoot Hive (folder)</p><p>To import this file on the infected PC, simply double click on the .REG file you just exported.</p><p>The .C variant also prevents you from viewing hidden files on your PC.<br
/> The following Batch file should resolve this problem:</p><p>@ECHO OFF<br
/> BREAK ON<br
/> reg.exe add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL /v CheckedValue /t REG_DWORD /d 0&#215;1 /f<br
/> pause<br
/> exit</p><p>Good Luck.</p> ]]></content:encoded> </item> <item><title>By: ary</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-2400</link> <dc:creator>ary</dc:creator> <pubDate>Tue, 24 Mar 2009 16:58:16 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-2400</guid> <description>The only site that I could access when I had downadap is bdtools.net, a BitDefender site. The removal tool there is great and they have one for networks also.</description> <content:encoded><![CDATA[<p>The only site that I could access when I had downadap is bdtools.net, a BitDefender site. The removal tool there is great and they have one for networks also.</p> ]]></content:encoded> </item> <item><title>By: Boris</title><link>http://www.precisesecurity.com/worms/w32downadup#comment-2262</link> <dc:creator>Boris</dc:creator> <pubDate>Mon, 16 Feb 2009 22:13:03 +0000</pubDate> <guid
isPermaLink="false">http://www.precisesecurity.com/threats/w32downadup/#comment-2262</guid> <description>This virus use admin share to infect other machines. It is very important to log of any administrator account, put some difficult password. You can use my computer/manage/share folders/sessions to see what computer is trying to infect. Very important is to check share folders for autorun.inf file. Also very important is to disable autorun options. Task scheduler service must be stop. Admin shares admin$, c$ must be stooped. This help me for a network of 200 computers and 20 servers. Use Symantec removal tool and Microsoft patch. Once computers are patched and AV database updated, virus can&#039;t infect them.
P.S.
For anyone who is boring with pop up messages from AV, disable admin and c shares on computer and it will stop. Scan and patch it and clear task scheduler.</description> <content:encoded><![CDATA[<p>This virus use admin share to infect other machines. It is very important to log of any administrator account, put some difficult password. You can use my computer/manage/share folders/sessions to see what computer is trying to infect. Very important is to check share folders for autorun.inf file. Also very important is to disable autorun options. Task scheduler service must be stop. Admin shares admin$, c$ must be stooped. This help me for a network of 200 computers and 20 servers. Use Symantec removal tool and Microsoft patch. Once computers are patched and AV database updated, virus can&#8217;t infect them.</p><p>P.S.<br
/> For anyone who is boring with pop up messages from AV, disable admin and c shares on computer and it will stop. Scan and patch it and clear task scheduler.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 5/5 queries in 0.003 seconds using disk: basic
Object Caching 417/417 objects using disk: basic

Served from: www.precisesecurity.com @ 2012-02-12 08:11:59 -->
