Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

help me w32.downadup.B

Updated: 09 Feb 2011 | 19 comments
fahad_noor@hotmail.com's picture
0 0 Votes
Login to vote

Hello all,
                     I am fahad from pakistan i am network administrator in private company,i have 70 client computers, all client computer are infected with this virus w32.downadup.B i am using SAV10 ,my domain controller is infected as well, sav only do take action partially not permanently, kindly help i do have use all removal but no one is working properly,thanks

Comments

sandip_sali's picture
25
Dec
2009
1 Vote +1
Login to vote

w32.downadup.B removal tool

Have you tried this ..

http://www.symantec.com/security_response/writeup....

Thanks & Regards Sandip C Sali

shp's picture
25
Dec
2009
1 Vote +1
Login to vote

Please install the following

Please install the following Patches (MS08-067,MS08-078) on all the computers without fail.

Check this link for more info..
https://www-secure.symantec.com/connect/articles/b...

 

Regards,
Srinivas H.P.
HCL Infosystems Ltd

cable mite's picture
26
Dec
2009
0 Votes 0
Login to vote

One more step

After you clean it up, ensure that you also check your services.
Background Intelligent Transfer Service & Windows Automatic Updates - both these services are disabled by downadup.
Ensure that you set both services to automatic.
Else you will not get any patches.

------------------------------------------------------------
MR99 will fix it all.

ShadowsPapa's picture
28
Dec
2009
0 Votes 0
Login to vote

BITS is supposed to be

BITS is supposed to be manual, not automatic.
Automatic update service is automatic, and starts BITS as needed.
So set the automatic updates to automatic, and BITS (background intelligent transfer service) to manual.
However, you have to setup updates in the control panel if you want automatic updates, otherwise you have to update manually.

riva11's picture
26
Dec
2009
1 Vote +1
Login to vote

Isolate infected computers

Another most important action is to isolate infected computers , this can prevent to spread the virus to the others ( if there are still free of virus..).


riva11's picture
26
Dec
2009
1 Vote +1
Login to vote

Patch MS08-067

 Don't forget to install at least the MS08-067 to all computers without this important patch.

Brian81's picture
27
Dec
2009
0 Votes 0
Login to vote
ahmed Sharabasy's picture
28
Dec
2009
0 Votes 0
Login to vote

we ware have this virus in

we ware have this virus in our network and it was genrator file which generat the virus, we couldnot catch it, i called symantec and they told me to download the microsoft monthly removel tool and it work and the file which generat  the virus was catch and the endpoint catch the virus.

Fatih Teke's picture
28
Dec
2009
0 Votes 0
Login to vote

Hello I was have downadup

Hello I was have downadup too.
I fixed my downadup problem.
-Update OS (critical,important and security updates)
-Update SEP
-change weak password.
-change domain admins members password (if they weak)
-Change administrator password if it weak
-create a daily reports.
-create a notifications (new virus detected,single risk event)
- change antivirus and antispy policy first action is delete
-follow the reports.
-check Users sharing

Thanks
Fatih.

 Everything works better when everything works together.

fahad_noor@hotmail.com's picture
29
Dec
2009
0 Votes 0
Login to vote

W32.downadup.B

well dear as i told you i am using sav 10 , and that sav10 is installed at domain controller, i can't receive any notifacation on server as i run removal script , problem is that clients computer are infected as you told you to install MS08-067 i did it , but once i D.exe finished, msg accur installed MS-08-067 patch as i installed already.

fahad_noor@hotmail.com's picture
29
Dec
2009
0 Votes 0
Login to vote
AravindKM's picture
29
Dec
2009
0 Votes 0
Login to vote

Try this Best Practice for

Try this
Best Practice for Downadup.B and Additional information on the same. 

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

fahad_noor@hotmail.com's picture
03
Jan
2010
0 Votes 0
Login to vote

not cleaned

Dear all i did it it many time but i am unable to  remove this virus, it need to disconnected all shared drives from domain controller ? and run windows in safe mode ?then run removal ? guide me please

fahad_noor@hotmail.com's picture
03
Jan
2010
0 Votes 0
Login to vote

password

as you said change my password i did it , i have changed my domain controller's administrator password, you mean i have to change all domain members password ?

AravindKM's picture
03
Jan
2010
0 Votes 0
Login to vote

Did you done evrything

Did you done everything according to the article provided above.?
Patch level and virus definition is up to date?
The MS paches KB960714&Kb958644 are most importent in your senario.
"as you said change my password i did it , i have changed my domain controller's administrator password, you mean i have to change all domain members password ?"
In fact all domain accounts should have a strong password.If it is not present pls change it.

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Subhani's picture
04
Jan
2010
0 Votes 0
Login to vote

Here is What worked for us

Dear Fahad ,

           I am not sure if your Problem is resolved Or you still need help however we faced a similar situation at customer end last year and as per my engineers , MSRT ( Microsoft Malicious Software Removal tool)  was working better as compared to any other Antivirus Software .Try that on your DC and few clients .
There is also another software named Combofix ( download from Bleepingcomputer.org) which is very useful however try it on one of the clients first .
Also download conficker detection tool from the URL mentioned below and scan your network .It will tell you how many machines are infected .For each machine ,do the following .

a) Remove network cable and Run MSRT or Combofix
b) Restart the machine .Apply Windows Patch .Restart again and than Scan the whole machine with SAV .
c) Once completely scanned and found clean ,connect the network cable back .

http://www.foundstone.com/us/resources-free-tools.asp

Hopefully it should help . Remember that it copies itself to USB Drives as well so you need to scan and clean all the USB Memory sticks Or hard disks which are being used in your company .

Aaed Alqarta's picture
14
Jan
2010
0 Votes 0
Login to vote

How to beat W32.Dowandup infections - Outbreak Scenario

Hi everyone, 
I've been solving virus infection problems since a long time, and W32.Downadup has a complete chapter. I've added a new article called (How to beat W32.Dowandup infections - Outbreak Scenario)
https://www-secure.symantec.com/connect/articles/how-beat-w32downadup-infections-outbreak-scenario
If you have any comments/issues you are welcome to speak

Authorized Symantec Consultant - Symantec Certified Specialist - Experts-Exchange Certified Guru

Please don't forget to mark your thread solved

josephheaven's picture
21
Jan
2010
0 Votes 0
Login to vote

w32.downloadup.b infection

I have to say that I am seriously disappointed with the performance of our Symantec Endpoint Protection which we have paid for for the last few years and it is unlikely that I will now be renewing as the software has completely failed to deal with this virus and despite following all the instructions here I am still firefighting this virus on our network of 20-25 PC's. The removal tool doesn't work, in fact AVG FREE Edition seems to find and remove more than this product, though still fails to completely remove it.

I thi9nk that my point is this. If we are PAYING for software to protect us, and it is failing to do so, and even to succeed with basic viruses you have to manually go to each PC, what are we supposed to do as IT Managers and Network Admins that are responsible for large numbers of client machines!? Is there not a product out there that WORKS??

Can someone, anyone, PLEASE come up with a sensible solution to this problem for Network Admins. So far all the solutions offered either fail completely or are just not practical/are unrealistic.

Symantec better come up with a network removal tool pronto if I'm to renew in feb.

Aaed Alqarta's picture
22
Jan
2010
0 Votes 0
Login to vote

@josepheaven Have you checked

@josepheaven

Have you checked my article on dealing with Downadup

Authorized Symantec Consultant - Symantec Certified Specialist - Experts-Exchange Certified Guru

Please don't forget to mark your thread solved