Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

W32.Downadup P2P Scanner Script for Nmap

Updated: 29 Jun 2009
Security Intel Analysis Team's picture
+1 1 Vote
Login to vote

Symantec’s Security Intelligence Analysis Team has collaborated with Nmap contributor Ron Bowes to aid in the development of an Nmap script that is able to detect hosts infected with W32.Downadup.C by enumerating the peer-to-peer (P2P) protocol used by the worm. The script has been made available to the public via nmap.org. The script has also been bundled in with the latest Nmap beta, nmap-4.85BETA8. If you are using an older version of Nmap that does not contain the Nmap scripting engine, you may want to download this updated version.

 

If you are new to using Nmap scripts I suggest that you check out Ron’s blog, which has lots of details on how to use the script with Nmap. Once you have located infected systems you can use the Symantec W32.Downadup Removal Tool to clean the infected system.