Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Cant clean W32_Downadup_B virus

Updated: 15 Jul 2010 | 5 comments
alex0120's picture
0 0 Votes
Login to vote

 How to clear this virus "W32_Downadup_B" on windows server 2003. I had tried scan SEP but the virus still prompt out. I download the removal also cant scan the virus. Any suggestion.

thank

discussion Filed Under:

Comments

Mithun Sanghavi's picture
04
Nov
2009
1 Vote +1
Login to vote

Plan of Action

Plan of Action:

1) Update ALL the clients with Latest Microsoft Service Packs and Security Patches
2) ALL machines need to be installed with Symantec Endpoint Protection with Latest Virus Defintions.
3) Disable System Restore from GPO till the threat has been removed
4) Disable the "AutoRun from GPO till the threat has been removed
5) Scan the Machine with Latest Virus defintions

Please check and work on the following Forums Article written for W32.Downadup.B :
 
https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same
 
OR
 
 
Simple steps to protect yourself from the Conficker Worm
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/3aa5a06c7bf48bd988257589006cd1e1?OpenDocument

*Note: When we say "All Computers", it means ALL COMPUTERS and NO COMPUTER should be MISSED.

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

HAROONKHANZ's picture
04
Nov
2009
0 Votes 0
Login to vote

http://www.symantec.com/secur

http://www.symantec.com/security_response/writeup.jsp?docid=2008-123015-3826-99
http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99

1)- check all server PC settings
no user without password i suggest 7 charactor atleast
disable guest
no share rights  with everyone write /change acess
2)- clear all sytem  folder of

d all of these via cmd cd to particular folder and run del/f/s/q *.*
temp  (windows \temp) (document and setting\user\localting\temp and temp insterne file )
recycled recycler recycle of all driver

disable system restore and take rights of sytem volumen information folder on all drive c: d: and run cmd then del /f/s/q *.*

deploye windows xp patch or (WindowsXP-KB957097-x86-ENU.exe,WindowsXP-KB958644-x86-ENU.exe, WindowsXP-KB958687-x86-ENU.exe,WindowsServer2003-KB958644-x86-ENU.exe)

start .MENU...RUN MSCONFIG ......SEE SERVICES TABLE DISABLE UKNOWN UN IDETIFIED SERVICES AND STOP EXTRA STARTUP

INSTALLA SYMANTEC ANTIVIRUS WITH LATEST RAPID RELEASE DEFINTION
www.symantec.com/avcenter/rapidrelease.download.

CONVERT ALL SYSTEM PARTITON DRIVE TO NTFS

Aaed Alqarta's picture
14
Jan
2010
0 Votes 0
Login to vote

How to beat W32.Dowandup infections - Outbreak Scenario

Hi everyone,

I've been solving virus infection problems since a long time, and W32.Downadup has a complete chapter. I've added a new article called (How to beat W32.Dowandup infections - Outbreak Scenario)

https://www-secure.symantec.com/connect/articles/how-beat-w32downadup-infections-outbreak-scenario

If you have any comments/issues you are welcome to speak

 

Authorized Symantec Consultant - Symantec Certified Specialist - Experts-Exchange Certified Guru

Please don't forget to mark your thread solved

jomargonzales's picture
14
Jan
2010
0 Votes 0
Login to vote

Try this

1.  Download and run WindowsServer2003-KB958644-x86-ENU.exe in Micorosft website. This is the patch for downadup.
2. Download and run Software Malicious Software Removal
http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en
3. Delete all AT*.job in the task scheduler.
4. Since this is a server, some clients of your server is still infected by Downadup. Try to clean the clients connected.
5. Be sure that SEP is updated since SEP can delete the said risks.
6. Are you inserting any removal drives? Maybe the threats come from the removal drives. Clean it.

I hope it helps.

Jomar Gonzales