Video Screencast Help

System Infacted Virus

Created: 27 Nov 2012 • Updated: 03 Dec 2012 | 8 comments
This issue has been solved. See solution.


Our lot of system are infacted virus problem.

Virus name :W32.Downadup

Check attach picture

Comments 8 CommentsJump to latest comment

Ashish-Sharma's picture


Check same thread

Check this comments

Mithun Sanghavi Symantec Employee Technical Support Accredited


Same issue in the current Thread:

Work on the Plan of Action as given below for a 100% result.

Plan of Action:

1) Make sure ALL Computers are installed with Symantec EP with latest / updated with virus defintions and

2) Install MS08-67 patch download [KB 958644] on ALL computer.

3) Install ALL Latest Microsoft Secuirty Patches / Sevice Packs on ALL machines

4) Disable Auto play with GPO

5) Disable Scheduled Tasks with GPO

6) Enable Security Auditing with GPO

7) Scan ALL the machines...

NOTE: *ALL means ALL client machines and server machines (make sure you don't miss any machine)

Inaddition to this, please check the Article provided below and work upon the same.

1) Best Practice for Downadup.B and Additional information on the same.

2) Simple steps to protect yourself from the Conficker Worm

Thanks In Advance

Ashish Sharma

pete_4u2002's picture

important thing is to apply the MS patch to all the machines in the environment. Are you using the IPS feature of SEP on these machines?

waelhilal's picture

Step 1 : Scan and remove W32.Downadup with this special tool

1. Download the Downadup removal tool from and save it on your Desktop or any accessible location.

This tool is available free. It can delete members of the Downadup family of Trojan. The tool is created with removal function; it cannot protect the computer from threats.

2. Double click on downloaded file, chose "Extract all files..." from the File menu, and follow the wizard's instructions. You can use any other archiver, like WinZip. This will create a folder called bd_rem_tool.

3. Double click on the file "bd_rem_tool_gui.exe" (or just "bd_rem_tool_gui"). Make sure that all files have been extracted from the zip archive, because all the contents are required for the removal tool to run. Follow the tool's instructions.

4. If you have Restricted Access (not Admin) on Windows Vista and XP, right click the "bd_rem_tool_gui" program and choose "Run as Administrator". Enter the computer Administrator User name and Password when prompted. This will scan the computer for presence of W32.Downadup. Remove all detected threats.

5. Reboot your computer when scanning is finished.

Step 2 : Run a scan with your antivirus program

1. Repeat the process of starting Windows in Safe Mode with Networking.
2. Open your antivirus program and download the most recent update. This method ensures that your antivirus program can detect even newer variants of W32.Downadup.

Updating your antivirus software is a one-click process. Please refer to your software manual for complete instructions.

3. Once updating is finished, run a full system scan on the affected PC. After the scan, delete all infected items. If unable to clean or delete, better place the threat in quarantine.

Step 3: Run another test with online virus scanner

Another way to remove W32.Downadup without the need to install additional antivirus software is to perform a thorough scan with free online virus scanner. It can be found on websites of legitimate antivirus and security provider.

1. Click the button below to proceed to the list of suggested Online Virus Scanner. Choose your desired provider. You can run each scan individually, one at a time, to ensure that all threats will be removed from the computer. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.

2. After completing the necessary download, your system is now ready to scan and remove W32.Downadup and other kinds of threats.
3. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
4. Remove or delete all detected items.
5. When scanning is finished, you may now restart the computer in normal mode.


Wael Hilal

Mobile: 00966531377132

Ashish-Sharma's picture


Also Check this

Best Practice for Downadup.B and Additional information on the same.

Thanks In Advance

Ashish Sharma

Mick2009's picture

An additional link that will be of interest:

The Downadup Codex, Edition 2.0

With thanks and best regards,


Nagesh Singh's picture

Hi Irk_Mar,

All system must have NTP as well as PTP component and Remove all sharing folder access where you are facing Downadup.B virus.

For more help go through the below artical.

Thanks & Regards,

Nagesh Singh

waelhilal's picture

@; padding-right: 27px; margin-right: 3px; font-weight: 700; line-height: 15px; color: rgb(65, 110, 0); font-family: helvetica, arial, clean, sans-serif; font-size: 12px; background-position: 100% -15px; background-repeat: no-repeat no-repeat;">ikr_mak did this solve your issue ?

Wael Hilal

Mobile: 00966531377132