Cant clean W32_Downadup_B virus
Updated: 15 Jul 2010 | 5 comments
How to clear this virus "W32_Downadup_B" on windows server 2003. I had tried scan SEP but the virus still prompt out. I download the removal also cant scan the virus. Any suggestion.
thank
discussion Filed Under:
Comments
Refer below articles
Best Practice for Downadup.B and Additional information on the same
Worms and threats that spread across networks by network shares have become more common in recent years.--Like Downadup/Conficker
How Symantec can help against Downadap, Kido and Conficker
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Plan of Action
Plan of Action:
1) Update ALL the clients with Latest Microsoft Service Packs and Security Patches
2) ALL machines need to be installed with Symantec Endpoint Protection with Latest Virus Defintions.
3) Disable System Restore from GPO till the threat has been removed
4) Disable the "AutoRun from GPO till the threat has been removed
5) Scan the Machine with Latest Virus defintions
Please check and work on the following Forums Article written for W32.Downadup.B :
https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same
OR
Simple steps to protect yourself from the Conficker Worm
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/3aa5a06c7bf48bd988257589006cd1e1?OpenDocument
*Note: When we say "All Computers", it means ALL COMPUTERS and NO COMPUTER should be MISSED.
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3
Follow me on Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo
http://www.symantec.com/secur
http://www.symantec.com/security_response/writeup.jsp?docid=2008-123015-3826-99
http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99
1)- check all server PC settings
no user without password i suggest 7 charactor atleast
disable guest
no share rights with everyone write /change acess
2)- clear all sytem folder of
d all of these via cmd cd to particular folder and run del/f/s/q *.*
temp (windows \temp) (document and setting\user\localting\temp and temp insterne file )
recycled recycler recycle of all driver
disable system restore and take rights of sytem volumen information folder on all drive c: d: and run cmd then del /f/s/q *.*
deploye windows xp patch or (WindowsXP-KB957097-x86-ENU.exe,WindowsXP-KB958644-x86-ENU.exe, WindowsXP-KB958687-x86-ENU.exe,WindowsServer2003-KB958644-x86-ENU.exe)
start .MENU...RUN MSCONFIG ......SEE SERVICES TABLE DISABLE UKNOWN UN IDETIFIED SERVICES AND STOP EXTRA STARTUP
INSTALLA SYMANTEC ANTIVIRUS WITH LATEST RAPID RELEASE DEFINTION
www.symantec.com/avcenter/rapidrelease.download.
CONVERT ALL SYSTEM PARTITON DRIVE TO NTFS
How to beat W32.Dowandup infections - Outbreak Scenario
Hi everyone,
I've been solving virus infection problems since a long time, and W32.Downadup has a complete chapter. I've added a new article called (How to beat W32.Dowandup infections - Outbreak Scenario)
https://www-secure.symantec.com/connect/articles/how-beat-w32downadup-infections-outbreak-scenario
If you have any comments/issues you are welcome to speak
Authorized Symantec Consultant - Symantec Certified Specialist - Experts-Exchange Certified Guru
Please don't forget to mark your thread solved
Try this
1. Download and run WindowsServer2003-KB958644-x86-ENU.exe in Micorosft website. This is the patch for downadup.
2. Download and run Software Malicious Software Removal
http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en
3. Delete all AT*.job in the task scheduler.
4. Since this is a server, some clients of your server is still infected by Downadup. Try to clean the clients connected.
5. Be sure that SEP is updated since SEP can delete the said risks.
6. Are you inserting any removal drives? Maybe the threats come from the removal drives. Clean it.
I hope it helps.
Jomar Gonzales
Would you like to reply?
Login or Register to post your comment.