Monday, January 26, 2009

Downadup worm removal

Downadup (also known as Conficker, Kido or Downandup) is a very dangerous worm malware, which already infected more than 9 millions computers according to some sources. It can be installed from infected USB drive or from the infected computer in the local network. If infected USB drive is plugged in to the computer, the user will see Autorun window, which may look like the following:



If the tricked user choose "Open folder to view files" item, Downadup worm installs itself on the target computer. Once installed it spreads over local network.

Downadup worm disables the following services on the infected computer:
- Windows Security Center Service
- Windows Update Auto Update Service
- Background Intelligence Transfer Service
- Windows Defender
- Error Reporting Service
- Windows Error Reporting Service

The user cannot access various security-related websites from the infected computer because Downadup worm blocks their domains. Downadup worm is able to morph oun code to prevent detection.

Downadup worm cannot be removed manually. Therefore, we recommend to use one of the existing removal tools.

Suggested Downadup worm Removal Tool

No comments: