How to Remove Conficker / Confickr / Downup / Downdaup Worm

March 31, 2009 – 9:58 pm

If your machine / your machine / your friend’s machine got infected by Conficker / Confickr / Downup / Downdaup worm, here are some of information about the worm, symptoms and removal tool that you may found useful to get rid of it.

how conficker virus spread

 

Brief information about Conficker worm

  • The worm attacks only Windows operating system
  • It exploits a known vulnerability in the Windows Server Service
  • Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Security Reporting.
  • Next, the worm downloads and installs additional malware on an infected computer.
  • The worm also attaches itself to a certain Windows processes such as svchost.exe, explorer.exe and services.exe, making it even harder to detect.

 

Why should I care / be afraid of it?

  • In just four days, the number of computers infected rose from 2.4 million to 8.9 million.
  • There are various variants of the worm so it is here to stay.

 

Your PC / network is probably infected when…

  • System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.
  • Account lockout policies being reset automatically.
  • You can’t access your antivirus provider sites such as “trendmicro”, “sophos”, etc. (cool and evil at the same time!)
  • Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and ErrorReporting Services are automatically disabled.
  • Domain controllers respond slowly to client requests.
  • Launches a brute force dictionary attack against administrator passwords to help it spread through ADMIN$ shares, making choice of sensible passwords advisable.

 

Conficker worm can infect computers / networks via..

  • The network (via svchost.exe)
  • Via removable drives, your USB thumb drive for example

 

Conficker has several other names / variants, for example:

  • TA08-297A
  • CVE-2008-4250
  • VU827267
  • Win32/Conficker.A
  • Mal/Conficker-A
  • Trojan.Win32.Agent.bccs
  • W32.Downadup.B
  • Trojan-Downloader.Win32.Agent.aqfw
  • W32/Conficker.worm
  • Trojan:Win32/Conficker!corrupt
  • W32.Downadup
  • WORM_DOWNAD
  • Confickr

 

How to prevent Conficker virus from infecting your computer

  • Apply the MS08-067 Windows Critical Security Update (and keep your Windows constantly updated!)
  • Disable removable drive autorun feature in your Windows system. Check out how to disable autorun feature here or you can just do it simply with Tweak UI.
  • Have some common sense, set your antivirus program to auto-update everyday.
  • Set a strong Windows administrator password.
  • Use other OS other than Windows (joking!)

 

My PC / has been infected, how do I remove Conficker – (Conficker Removal Tool) ?

 

There you go, some information and Conficker removal tool to prepare you for the worm onslaught (if you are “lucky” to meet one!)

Tags: , , , , , ,

Bookmark This Post
  • Print
  • Digg
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • Reddit
  • Twitter

You come again! Maybe it is the right time to subscribe to my RSS feed. Thanks for the support!

Related Posts:


  1. 4 Responses to “How to Remove Conficker / Confickr / Downup / Downdaup Worm”

  2. Switch to other OS is probably the best solution. :p I think my personal computer has caught by conficker too but I think my antivirus – NOD32 has removed it or terminated the action of the virus. :) (Hopefully… )

    By Kit Kat on May 19, 2009

  3. lol. that is one good solution.

    By Syahid A. on May 19, 2009

  4. It’s the best solution. :p

    By Kit Kat on May 20, 2009

  5. I have found an easiest method for securing and removing conficker worm at this forum check the link: http://techteem.com/forum/viewtopic.php?f=28&t=921

    IF your are infected or not this forum has both methds for you to secure or to remove conficker from your pc

    By Kamran on Feb 20, 2010

Post a Comment

Clicky Web Analytics