Video Screencast Help

System Infacted Virus

Created: 27 Nov 2012 • Updated: 03 Dec 2012 | 8 comments
This issue has been solved. See solution.

HI,

Our lot of system are infacted virus problem.

Virus name :W32.Downadup

Check attach picture

Comments 8 CommentsJump to latest comment

Ashish-Sharma's picture

HI,

Check same thread

https://www-secure.symantec.com/connect/forums/virus-information

https://www-secure.symantec.com/connect/forums/w32downadupb-pop-ups

 

Check this comments

Mithun Sanghavi Symantec Employee Technical Support Accredited

Hello,

Same issue in the current Thread: https://www-secure.symantec.com/connect/forums/virus-information

Work on the Plan of Action as given below for a 100% result.

Plan of Action:

1) Make sure ALL Computers are installed with Symantec EP with latest / updated with virus defintions and

2) Install MS08-67 patch download [KB 958644] on ALL computer.

http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

3) Install ALL Latest Microsoft Secuirty Patches / Sevice Packs on ALL machines

4) Disable Auto play with GPO

http://support.microsoft.com/kb/953252

5) Disable Scheduled Tasks with GPO

http://support.microsoft.com/kb/310208

6) Enable Security Auditing with GPO

http://support.microsoft.com/kb/300549

7) Scan ALL the machines...

NOTE: *ALL means ALL client machines and server machines (make sure you don't miss any machine)

Inaddition to this, please check the Article provided below and work upon the same.

1) Best Practice for Downadup.B and Additional information on the same.

https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same

2) Simple steps to protect yourself from the Conficker Worm

http://www.symantec.com/docs/TECH93179

 

Thanks In Advance

Ashish Sharma

 

 

SOLUTION
pete_4u2002's picture

important thing is to apply the MS patch to all the machines in the environment. Are you using the IPS feature of SEP on these machines?

waelhilal's picture

 

Step 1 : Scan and remove W32.Downadup with this special tool

1. Download the Downadup removal tool from http://download.precisesecurity.com/bd_rem_tool.zip and save it on your Desktop or any accessible location.

This tool is available free. It can delete members of the Downadup family of Trojan. The tool is created with removal function; it cannot protect the computer from threats.

2. Double click on downloaded file, chose "Extract all files..." from the File menu, and follow the wizard's instructions. You can use any other archiver, like WinZip. This will create a folder called bd_rem_tool.

3. Double click on the file "bd_rem_tool_gui.exe" (or just "bd_rem_tool_gui"). Make sure that all files have been extracted from the zip archive, because all the contents are required for the removal tool to run. Follow the tool's instructions.

4. If you have Restricted Access (not Admin) on Windows Vista and XP, right click the "bd_rem_tool_gui" program and choose "Run as Administrator". Enter the computer Administrator User name and Password when prompted. This will scan the computer for presence of W32.Downadup. Remove all detected threats.

5. Reboot your computer when scanning is finished.

Step 2 : Run a scan with your antivirus program

1. Repeat the process of starting Windows in Safe Mode with Networking.
2. Open your antivirus program and download the most recent update. This method ensures that your antivirus program can detect even newer variants of W32.Downadup.

Updating your antivirus software is a one-click process. Please refer to your software manual for complete instructions.

3. Once updating is finished, run a full system scan on the affected PC. After the scan, delete all infected items. If unable to clean or delete, better place the threat in quarantine.

Step 3: Run another test with online virus scanner

Another way to remove W32.Downadup without the need to install additional antivirus software is to perform a thorough scan with free online virus scanner. It can be found on websites of legitimate antivirus and security provider.

1. Click the button below to proceed to the list of suggested Online Virus Scanner. Choose your desired provider. You can run each scan individually, one at a time, to ensure that all threats will be removed from the computer. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.

2. After completing the necessary download, your system is now ready to scan and remove W32.Downadup and other kinds of threats.
3. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
4. Remove or delete all detected items.
5. When scanning is finished, you may now restart the computer in normal mode.

reference: http://www.precisesecurity.com/worms/w32downadupe

Wael Hilal

Mobile: 00966531377132

Ashish-Sharma's picture

HI,

Also Check this

Best Practice for Downadup.B and Additional information on the same.

https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same

Thanks In Advance

Ashish Sharma

 

 

Mick2009's picture

An additional link that will be of interest:

The Downadup Codex, Edition 2.0
https://www-secure.symantec.com/connect/blogs/downadup-codex-edition-20

With thanks and best regards,

Mick

Nagesh Singh's picture

Hi Irk_Mar,

All system must have NTP as well as PTP component and Remove all sharing folder access where you are facing Downadup.B virus.

For more help go through the below artical.

https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same#comment-8019741

Thanks & Regards,

Nagesh Singh

 

waelhilal's picture

@ikr_mak did this solve your issue ?

Wael Hilal

Mobile: 00966531377132