Endpoint Protection

 View Only
Expand all | Collapse all

help me w32.downadup.B

ℬrίαη

ℬrίαηDec 27, 2009 08:29 PM

Migration User

Migration UserDec 30, 2009 12:10 AM

  • 1.  help me w32.downadup.B

    Posted Dec 26, 2009 12:46 AM
    Hello all,
                         I am fahad from pakistan i am network administrator in private company,i have 70 client computers, all client computer are infected with this virus w32.downadup.B i am using SAV10 ,my domain controller is infected as well, sav only do take action partially not permanently, kindly help i do have use all removal but no one is working properly,thanks


  • 2.  RE: help me w32.downadup.B



  • 3.  RE: help me w32.downadup.B

    Posted Dec 26, 2009 01:30 AM
    Please install the following Patches (MS08-067,MS08-078) on all the computers without fail.

    Check this link for more info..
    https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same

     


  • 4.  RE: help me w32.downadup.B

    Posted Dec 26, 2009 04:10 AM
    After you clean it up, ensure that you also check your services.
    Background Intelligent Transfer Service & Windows Automatic Updates - both these services are disabled by downadup.
    Ensure that you set both services to automatic.
    Else you will not get any patches.


  • 5.  RE: help me w32.downadup.B

    Posted Dec 26, 2009 04:29 AM
    Another most important action is to isolate infected computers , this can prevent to spread the virus to the others ( if there are still free of virus..).




  • 6.  RE: help me w32.downadup.B

    Posted Dec 26, 2009 04:31 AM
     Don't forget to install at least the MS08-067 to all computers without this important patch.


  • 7.  RE: help me w32.downadup.B

    Posted Dec 27, 2009 08:29 PM
    Also, change user's login password


  • 8.  RE: help me w32.downadup.B

    Posted Dec 28, 2009 08:43 AM

    we ware have this virus in our network and it was genrator file which generat the virus, we couldnot catch it, i called symantec and they told me to download the microsoft monthly removel tool and it work and the file which generat  the virus was catch and the endpoint catch the virus.



  • 9.  RE: help me w32.downadup.B

    Posted Dec 28, 2009 09:14 AM
    BITS is supposed to be manual, not automatic.
    Automatic update service is automatic, and starts BITS as needed.
    So set the automatic updates to automatic, and BITS (background intelligent transfer service) to manual.
    However, you have to setup updates in the control panel if you want automatic updates, otherwise you have to update manually.


  • 10.  RE: help me w32.downadup.B

    Posted Dec 28, 2009 10:42 AM
    Hello I was have downadup too.
    I fixed my downadup problem.
    -Update OS (critical,important and security updates)
    -Update SEP
    -change weak password.
    -change domain admins members password (if they weak)
    -Change administrator password if it weak
    -create a daily reports.
    -create a notifications (new virus detected,single risk event)
    - change antivirus and antispy policy first action is delete
    -follow the reports.
    -check Users sharing

    Thanks
    Fatih.


  • 11.  RE: help me w32.downadup.B

    Posted Dec 30, 2009 12:06 AM
    well dear as i told you i am using sav 10 , and that sav10 is installed at domain controller, i can't receive any notifacation on server as i run removal script , problem is that clients computer are infected as you told you to install MS08-067 i did it , but once i D.exe finished, msg accur installed MS-08-067 patch as i installed already.


  • 12.  RE: help me w32.downadup.B

    Posted Dec 30, 2009 12:10 AM
    help


  • 13.  RE: help me w32.downadup.B



  • 14.  RE: help me w32.downadup.B

    Posted Jan 03, 2010 11:28 PM

    Dear all i did it it many time but i am unable to  remove this virus, it need to disconnected all shared drives from domain controller ? and run windows in safe mode ?then run removal ? guide me please



  • 15.  RE: help me w32.downadup.B

    Posted Jan 03, 2010 11:36 PM
    as you said change my password i did it , i have changed my domain controller's administrator password, you mean i have to change all domain members password ?


  • 16.  RE: help me w32.downadup.B

    Posted Jan 04, 2010 12:10 AM
    Did you done everything according to the article provided above.?
    Patch level and virus definition is up to date?
    The MS paches KB960714&Kb958644 are most importent in your senario.
    "as you said change my password i did it , i have changed my domain controller's administrator password, you mean i have to change all domain members password ?"
    In fact all domain accounts should have a strong password.If it is not present pls change it.


  • 17.  RE: help me w32.downadup.B

    Posted Jan 04, 2010 02:49 AM
    Dear Fahad ,

               I am not sure if your Problem is resolved Or you still need help however we faced a similar situation at customer end last year and as per my engineers , MSRT ( Microsoft Malicious Software Removal tool)  was working better as compared to any other Antivirus Software .Try that on your DC and few clients .
    There is also another software named Combofix ( download from Bleepingcomputer.org) which is very useful however try it on one of the clients first .
    Also download conficker detection tool from the URL mentioned below and scan your network .It will tell you how many machines are infected .For each machine ,do the following .

    a) Remove network cable and Run MSRT or Combofix
    b) Restart the machine .Apply Windows Patch .Restart again and than Scan the whole machine with SAV .
    c) Once completely scanned and found clean ,connect the network cable back .

    http://www.foundstone.com/us/resources-free-tools.asp

    Hopefully it should help . Remember that it copies itself to USB Drives as well so you need to scan and clean all the USB Memory sticks Or hard disks which are being used in your company .


  • 18.  RE: help me w32.downadup.B

    Posted Jan 14, 2010 04:33 AM
    Hi everyone, 
    I've been solving virus infection problems since a long time, and W32.Downadup has a complete chapter. I've added a new article called (How to beat W32.Dowandup infections - Outbreak Scenario)
    https://www-secure.symantec.com/connect/articles/how-beat-w32downadup-infections-outbreak-scenario
    If you have any comments/issues you are welcome to speak


  • 19.  RE: help me w32.downadup.B

    Posted Jan 21, 2010 05:12 AM
    I have to say that I am seriously disappointed with the performance of our Symantec Endpoint Protection which we have paid for for the last few years and it is unlikely that I will now be renewing as the software has completely failed to deal with this virus and despite following all the instructions here I am still firefighting this virus on our network of 20-25 PC's. The removal tool doesn't work, in fact AVG FREE Edition seems to find and remove more than this product, though still fails to completely remove it.

    I thi9nk that my point is this. If we are PAYING for software to protect us, and it is failing to do so, and even to succeed with basic viruses you have to manually go to each PC, what are we supposed to do as IT Managers and Network Admins that are responsible for large numbers of client machines!? Is there not a product out there that WORKS??

    Can someone, anyone, PLEASE come up with a sensible solution to this problem for Network Admins. So far all the solutions offered either fail completely or are just not practical/are unrealistic.

    Symantec better come up with a network removal tool pronto if I'm to renew in feb.


  • 20.  RE: help me w32.downadup.B

    Posted Jan 22, 2010 02:16 AM
    @josepheaven

    Have you checked my article on dealing with Downadup